Repository navigation
fix(e2e): install reviewed SDK for MCP bridge - #12222
Conversation
Signed-off-by: Deepak Jain <deepujain@gmail.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (5)
Included review availability: Your plan provides up to 12 included reviews per hour; 10 remain after this review. 📝 WalkthroughWalkthroughThe E2E workflow now installs the reviewed OpenShell SDK before restoring MCP bridge CLI artifacts. Boundary validation requires this dependency, artifact download, shared installation, and ordering. Tests cover missing dependencies and installation steps. ChangesReviewed SDK MCP bridge integration
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The MCP bridge workflow now installs the reviewed SDK before restoring CLI artifacts, with validation enforcing the required contract. No merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 14.29% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 4 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 2📝 Generate docstrings 💡
🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall line coverage in commit a23fcf8 in the TypeScript / code-coverage/cliThe overall line coverage in commit a23fcf8 in the Show a line coverage summary of the most impacted files.
Updated |
|
PR Review Advisor finished for commit Request review only when Require no Advisor blockers is green. |
## Outcome Ordinary sandbox commands, probes and diagnostics use native OpenShell execution. Failed or ambiguous commands do not retry through SSH or privileged local execution. Supported provider recovery, interactive SSH and file transfer retain their existing authority checks. ## Reason Multiple ordinary-command transports could run equivalent commands with different identities or repeat an ambiguous mutation through a more privileged path. ### Related issues Fixes #11263, part of #11255. Includes merged prerequisites #12214, #12222, #12236, #11911, #12258 and #12256. ## Changes - Remove ordinary SSH execution, compatibility wiring and privileged fallbacks. Preserve named-gateway targeting, runtime identity, filtered environments, timeouts and distinguishable failures. - Route status through the same native executor while preserving its deadline and nullable transport-failure behavior. The OpenClaw readiness probe also preserves unavailable transport evidence after integrating #12256. - Retire unsupported custom gateway SSH recovery after auditing shipped manifests. Keep supported recovery, interactive access and file transfer. - Prevent WeChat removal when orphaned physical-session cleanup cannot be confirmed; document that behavior even without a channel entry. - Refresh corporate-CA trust through native stop/start of the same sandbox, and bound/redact MCP diagnostics. - Avoid evaluating a sandbox-controlled shell file for ordinary commands, and test actual process boundaries to reject SSH retries. ## Verification Current candidate: `836320e005cdb041c28afe12a7986bd4b8f05a5a`, integrating canonical `main` at `350a9863cd83b5a8ee7932d4ab916393d7e69279`. The merge resolves the base conflict, preserves the newer bounded MCP HTTPS diagnostics, and repairs native-version CLI fixtures to emit the required sandbox-exec marker while rejecting SSH fallback. The final follow-up pins the Hermes diagnostics support test to its asserted runtime and restores the ambient environment after each case. Local evidence: 14 CLI integration tests, 94 E2E-support tests, and 72 focused transport/version/debug tests passed. CLI TypeScript passed with an 8 GiB heap ceiling; lint, formatting, all 18 repository checks, signed commit hooks, publication validation, and pre-push CLI/plugin TypeScript checks passed. Hosted CI on this exact head is green, including all 12 CLI shards, aggregate CLI, managed startup for OpenClaw/Hermes/Deep Agents Code, exact all-agent activation on Docker and rootless Podman, both Pi image builds, rootless lifecycle and portable profile, CodeQL, audits, docs, and static checks. The only red attempt was an external HTTP 429 fetching the pinned Hermes archive; its single rerun passed. The earlier managed-image failure at `ceca9ae56` was an external `ImagePullFailed` ("bytes remaining on stream"); fail-closed cleanup remained intact and the explicit OpenShell cleanup removed the sandbox. Evidence below that names another candidate or says current-head is historical for `836320e00`. Previous candidate: `3caba6799cc006bd6ee2a891719509d73f773d73`. This follows the conflict-resolution merge `908a0b4`, which integrated main `2e162f266f583d78392494feff44c360d1390ad0`, without another base integration. The follow-up preserves later diagnostics and archive creation when endpoint authority refuses sandbox-internals collection. Cancellation and unexpected errors still propagate. It replaces an obsolete nullable DeepAgents transport mock with typed failure coverage and adds public-create coverage proving corporate-CA refresh finishes before registration. All 94 tests across seven affected suites passed, along with CLI TypeScript, source-shape, lint and formatting. Independent review, signed commit hooks, isolated pre-push validation, container cleanup and actual push hooks passed. Current-head [required CI](https://github.com/NVIDIA/NemoClaw/actions/runs/35967107832), [all nine Advisor reports and aggregate](https://github.com/NVIDIA/NemoClaw/actions/runs/35968484852), substantive CodeRabbit review, [managed images](https://github.com/NVIDIA/NemoClaw/actions/runs/35967107774), and [portable rootless checks](https://github.com/NVIDIA/NemoClaw/actions/runs/35967107785) passed. Image qualification covered all three agents on Docker and rootless Podman, with 36 activation turns and 18 cleanup actions total. Five current-head manual runs passed: - [Native CPU startup](https://github.com/NVIDIA/NemoClaw/actions/runs/35969691815): all three agents on AMD64 and ARM64; cleanup verified. - [Docker onboarding](https://github.com/NVIDIA/NemoClaw/actions/runs/35971477529): three repair/resume scenarios; 28 cleanup actions. - [Standard Docker lifecycle](https://github.com/NVIDIA/NemoClaw/actions/runs/35972475425): eight scenarios; 38 cleanup actions. - [Docker MCP](https://github.com/NVIDIA/NemoClaw/actions/runs/35973673916): all three agents and the credential-generation-window test; 51 cleanup actions, including explicit successful removal of all three private relays. - [Hermes Docker lifecycle](https://github.com/NVIDIA/NemoClaw/actions/runs/35975851054): all eight phases, including restart, ACP and configuration integrity; seven cleanup actions. These results qualify the stated scopes only. Remaining Podman lifecycle prerequisites, development-runtime policy disposition and unexecuted provider/protected scopes still prevent a full review-readiness claim. At parent `908a0b4`, managed images activated all three agents on Docker and Podman: 18 turns and nine cleanup passes per runtime. Its portable rootless fixture failed an initial PID identity check before onboarding. The unchanged fixture passed ten isolated Linux cycles, but the hosted cause remains unresolved. Neither result qualifies this new candidate. ### Historical evidence The following results belong to earlier commits and do not qualify the current candidate. The transport repair moves ordinary execution and its environment wrapper into the sandbox transport adapter, retargets all callers, improves public health-outcome coverage, and gives the OpenClaw skill fixture an account-home workspace with immediate cleanup registration. - Local affected suites: 1,234 tests passed, with 14 skips; 943 additional integration tests passed, with 15 skips. The sole remaining affected-suite failure is the unchanged Hermes Python fixture on a host without PyYAML. The dependency-boundary follow-up passed 466 targeted tests. TypeScript, lint, formatting, mock/live parity, focused cleanup tests and the architecture census passed; four stale architecture limits were lowered, with no increases. Current-head hosted evidence remains required after publication. - At `81936456060c102fe1d88795ffe31f6830d39a6a`, CI passed and all nine Advisor reports were inspected. The architecture finding and CodeRabbit's startup-test duplication finding are addressed by this repair. - [Live validation at 8193645](https://github.com/NVIDIA/NemoClaw/actions/runs/35832734620) finished with 41 selected scenarios passing and 17 failing. Thirteen Podman scenarios reported incompatible or ambiguous gateway ownership; another failed rebuild preflight. The selected-gateway runtime fix is isolated in #12267 and has not yet qualified this main PR. - Other failures: Docker provider selection exceeded its 8-second budget; the protected amd64 OpenClaw normalization probe timed out; and the Docker skill fixture failed finalization. The unsafe skill workspace placement is corrected here, but the complete live failure cause has not been proved. No latency, timeout, or baseline waiver is claimed. - Of 64 ordinary cleanup receipts, 63 were clear. Skill CLI cleanup failed; its fallback sandbox deletion, gateway removal and home cleanup passed. Both protected qualification daemon-removal receipts passed. Historical results do not qualify the new commit. - At parent `85256b3`, CI and all nine Advisor reports passed. Exact managed images activated all three agents on Docker and Podman, with 18 turns and nine clean teardown actions per runtime. CodeRabbit identified two dead duplicate mock setups; the preceding test-only correction replaces them with fail-fast unexpected-call stubs and explicit zero-call assertions. All 52 focused/growth tests, source-shape and parity checks passed. The trusted matcher still requires fresh managed-image qualification for this candidate; no ancestor-image override is used. - At parent `4c4dc76`, CI and CodeRabbit passed. All nine Advisor reports were collected; one reduction finding identified an impossible null return in the native-command facade type. The current repair narrows that contract and removes unreachable direct-consumer branches, retaining explicit typed transport-error mappings and remote nonzero exit handling. 364 affected tests passed, 14 skipped; seven growth tests, TypeScript, parity, source-shape, lint and formatting passed. Docker and Podman core image activation passed at that parent, but its image workflow failed an upstream Pi Perl DNS test. No parent result clears the current commit. - Advisor additionally requires the OpenShell gateway-auth contract scenario. It remains part of the outstanding current-head E2E work. ## Review notes The merged Podman artifact renewal and full-install cleanup prerequisite are included. Remaining fixture prerequisites are #12267 (Hermes ACP Podman context) and #12269 (MCP cleanup). Full Podman lifecycle coverage remains pending. Protected GPU coverage needs the offline npm prerequisite. Observer coverage is tracked by #12238/#12197. The dev MCP lane conflicts with the supported installer channel and needs disposition. Real-provider messaging and exact staging Launchable coverage are not claimed. No human approval, gate waiver or merge-readiness claim is made. --- Signed-off-by: Deepak Jain <deepujain@gmail.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Improvements** * Sandbox version checks, diagnostics, and maintenance commands now use native OpenShell execution. * Managed sandbox onboarding refreshes corporate CA trust before completing setup when a CA is configured. * CLI recovery messages now direct you to relevant OpenShell commands. * **Reliability** * Channel removal stops when cleanup cannot be confirmed, rather than proceeding with an uncertain result. * Sandbox transport failures are reported without retrying through SSH or a local runtime. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Deepak Jain <deepujain@gmail.com> Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Prekshi Vyas <prekshiv@nvidia.com>
## Outcome OpenClaw now owns its native configuration lifecycle after onboarding. NemoClaw no longer hashes, seals, repairs, selectively reconstructs, quarantines, or vetoes ordinary `openclaw.json` changes; rebuild and restore preserve the complete credential-sanitized native configuration. ## Reason OpenShell already owns the selected filesystem, credential, process, and network-policy boundaries. The retired NemoClaw configuration controller duplicated that ownership and could reject or overwrite valid OpenClaw changes. ### Related issues Closes #11764 Refs #11768 ## Changes - Delete the OpenClaw config guard, integrity hashes, seals, baselines, repair and quarantine paths, selective merge helpers, and their implementation-specific tests. - Restore the complete credential-sanitized OpenClaw state instead of reconstructing an allowlisted subset. Nested credentials remain excluded; non-secret native settings, including gateway settings, remain intact. - Route the remaining required OpenClaw mutations through `openclaw config set` or `unset` inside the sandbox. Serialized values travel on stdin rather than the host process argument list. - Keep host `nemoclaw config set` scoped to Hermes and direct OpenClaw users to the native CLI. - Update inference, MCP, tunnel, messaging, startup, rebuild, snapshot, doctor, E2E, and documentation contracts for native ownership. - Regenerate the reviewed managed-startup runtime bundle. ## Verification Current candidate `20d24596569b6787a7b5f1e7a10856244f95b619` is conflict-free and mergeable against exact base `7e1310c08c5137d5f5d4854a9de59b9a25af1fa1`. It fixes the duplicate Kao and rsliter P1 by printing a conditional second `start` after a marker-consuming start leaves OpenClaw stopped, covers both unverified-abort sibling paths, updates both owning documentation pages, and resolves the sole upstream conflict while preserving native configuration ownership and current main behavior. Focused snapshot and exec validation passed 36 tests with one skipped; all 157 exec CLI tests, all 18 repository checks, CLI type checking, documentation validation, normal commit hooks, and pre-push publication validation passed. All three new commits are GitHub Verified. Replacement CI, Images, and automated review are pending. The prior CI, Images, and E2E evidence below is historical and does not qualify this head. No new E2E was dispatched and no merge was performed. ### Conflict preservation and native-model proof — `e81a14aa6b` Published candidate: `e81a14aa6bf75ba9a515c90807e5c12bec292835`, including repair `c132cce5f6ed526aaa236e64dfcb872f034644ff`. One guarded push succeeded; fresh API and SSH agree after initial API lag. All 80 PR commits are Verified. The smaller restart fixture removes the need for policy PR #12338 or a #12120 growth exception. #12338 is closed without merging; no policy integration is required. - Restore PR code and tests lost by external bot merge `c7dd361e`: bounded restore diagnostics, native MCP registration and failure tests, recorded-runtime channel tests, live MCP failure evidence, and lifecycle text. Preserve main's single-command transport, no-fallback failures, stopped-state-first WeChat cleanup, readiness diagnostics and parity entries. Retired config/hash paths stay deleted. - Strengthen the native-model restart proof: send a credential-free JSON patch through native OpenClaw stdin to select a UUID-scoped provider using the already-tested model through `inference.local`. After stop/start, require persisted selection and a gateway-only turn reporting that provider/model and PONG before restoring the original selection and removing temporary entries. Native validation, launch checks and credential scanning remain. Contributor E2E guidance is updated; no new public surface is added. - Delete the custom configuration-cloning program and its now-unneeded validation and error-handling branches: one generated block and six generated conditions are removed, not moved elsewhere. Deterministic patch construction and unique-name checks belong to `e2e-support`; native CLI diagnostics retain fixture redaction. The regenerated census has 234 unique generated blocks and 829 conditions, with seven transitive blocks for `full-e2e`. Unique counts remain 1,790 expect calls and 3,371 assertion points. Growth checks pass with an empty exception policy against both PR base `7d02fef6` and main `f3282ba1`. The previously approved larger budget transition is not used; the #12120 exception is removed. - Refresh Pi receipts from original AMD64/ARM64 artifacts 10876299906/10876722335 in [Images 36162139959, attempt 2](https://github.com/NVIDIA/NemoClaw/actions/runs/36162139959/attempts/2). Both c7dd producer jobs passed publication, credential removal, digest validation, declared-entrypoint execution and contract upload. Receipt bytes and all Pi image inputs match the producer. The parent Images run failed CLI activation builds; Pi publication is not passing whole-image qualification. - Before the reduction, 215 unique focused tests, 22 Pi receipt integration tests, CLI/plugin builds, CLI typecheck, lint, parity, census and architecture checks passed in isolation. Normal c132 commit hooks passed after stale receipts and formatting were corrected. The reduction passed 153 unique focused tests across isolated runs and trusted lint. Client-suite setup first failed on a read-only cache, then four cases lacked a compiled shared module; isolated setup corrections resolved both. Census, empty-policy growth, parity, normal commit hooks, pre-push publication validation and CLI TypeScript passed without a bypass. Plugin/JavaScript pre-push lanes skipped unchanged paths. - Parent c7dd [CI 36162140057](https://github.com/NVIDIA/NemoClaw/actions/runs/36162140057) and Images failed on missing diagnostic exports; related CodeQuality/CodeQL findings are accepted in this restoration. Docker evidence was absent after failed setup; Podman also reported an unbound guard-log variable, so cleanup success is not established. Advisor did not execute after failed CI; paused CodeRabbit is not approval. - Independent writer review covers c132's 18-file tree and the committed reduction with no blockers. Credential review reconciled all 289 changed paths against base `7d02fef6`, then the seven-file reduction, to final tree `5f71521763fde2d6bed1e60cecc712b505793336`; no additional PR-owned credential defect was found. Current CI/images/automated feedback and dispatch checks remain required. The single authorized full-default PR E2E is unused. Historical failures and cleanup uncertainty below remain unresolved; no merge approval is claimed. The old heartbeat remains paused. ### Diagnostic log repair — `054109841cc9af1e6c8630bae626d0c220283675` - Fixed a PR-owned diagnostic leak: reading a log tail before host redaction could retain a credential fragment. Oversized logs now return metadata without content. Logs changed during reading are also omitted. Small stable regular logs retain whole-content redaction. - Reproduced a 24-character synthetic credential fragment on parent `e8c6796`. This fixture is absent on base `8283244`; no real credentials were used. The new regression fails with the old reader and passes with the repair. - All 13 focused tests passed: `vitest run --maxWorkers=1 --project e2e-support test/e2e/support/openclaw-container-diagnostics.test.ts test/e2e/support/openclaw-onboard-diagnostics.test.ts`. Coverage includes links, bounded reads, complete-value redaction and a log that grows during reading. - Oxfmt, Oxlint, CLI/plugin builds and CLI typecheck passed in the pinned isolated container. Validators came from canonical main `3a4eb285aee17d2c57ce991dc6fed93bad315d53`. The unprivileged container had no network, host home, Git directory, credentials or Docker socket. A disposable internal Git snapshot supplied build metadata. Normal pre-commit and commit-msg checks passed with `SKIP` unset. - The three-file repair changes the fixture, its support test and `test/e2e/docs/README.md`. It adds no dependency and changes no live assertion, budget, workflow selector or retry. The source diff contains no real credentials. Independent writer `/root/docs_finish_12120` reviewed the repair and evidence with no blockers. - Parent `e8c6796` CI [36113648857](https://github.com/NVIDIA/NemoClaw/actions/runs/36113648857) and Images [36113648882](https://github.com/NVIDIA/NemoClaw/actions/runs/36113648882) passed. All five image publication contracts and both Docker/rootless Podman activation artifacts were verified. Each activation artifact reports 18 turns and nine successful cleanup rows. This evidence is historical and does not qualify the new commit. - All nine parent Advisor specialists in [36115061651](https://github.com/NVIDIA/NemoClaw/actions/runs/36115061651) succeeded. Eight reported no findings. Documentation finding `F-documentation-standard-work-975a9196cba78a2c8db1` is a false positive: pinned OpenClaw 2026.9.1 copies native configuration into `.bak` before replacement, while NemoClaw sanitizes a separate captured snapshot. Primary and independent review confirmed the warning at `docs/inference/set-up-sub-agent.mdx:305` is accurate. The warning remains; the Advisor blocker gate remains failed, not waived or rerun. - Replacement CI, images and automated reviews remain required. The full-PR credential review is incomplete, so the one authorized full-default PR E2E has not been dispatched. No main integration or PR merge was performed. Historical OpenClaw resume failure remains unresolved. ### Root startup and credential-retention follow-up — `e8c6796bfda893a082b869e258920b848553fccb` - Remove a retired helper from root-mode authentication setup. The actual dispatch failed before entering the sandbox child; three test stubs hid the missing dependency. Removing those stubs exposed five failures. After the one-line production repair, all 127 tests in the three affected integration files passed. Authentication, managed credential clearing, failure propagation and temporary-script cleanup assertions remain unchanged. - This is PR-specific: the same isolated extraction fixture passes on base `828324444336b8bd2fda30c9fc537f0612088ece` and fails on parent `d3b11155f93f1b4ad9fefebd8eab7c6788d331b9`. The workspace-seeding sibling uses an existing helper and needs no change. Non-root startup does not use the repaired wrapper. - Correct the sub-agent guide: native write or Docker transport failure can leave completion uncertain, and native backups or rejected payloads can retain credentials. Preserve the supported stdin command and all eight code blocks. No destructive cleanup is added. Documentation build passed with zero errors and two existing Fern warnings. - [Advisor 36110894987](https://github.com/NVIDIA/NemoClaw/actions/runs/36110894987) ran all nine specialists successfully. Eight were clear. The documentation finding that `config patch --stdin` is unsupported is a false positive: OpenClaw 2026.9.1 registers that command. Its official archive checksum matches the Dockerfile pin. The two distinct safety claims above were found while verifying the command. The failed blocker gate is retained in the record; no Advisor rerun occurred. - Parent d3 passed [CI 36109551183](https://github.com/NVIDIA/NemoClaw/actions/runs/36109551183), all 12 CLI shards, and [Images 36109551043](https://github.com/NVIDIA/NemoClaw/actions/runs/36109551043). Five published image contracts identify d3. Docker and rootless Podman activation each recorded 18 agent turns, zero builds and nine successful cleanup actions with no failures. These results do not qualify the new commit. - Tests ran in a pinned, unprivileged, network-disabled container without host credentials, home or Docker socket. No assertion, E2E limit, dependency, validator or policy changed. The file-size ratchet decreases by one line to match the removed test stub, as required by the first commit-hook result. Main `3a4eb285aee17d2c57ce991dc6fed93bad315d53` was fetched for comparison; no integration was required. Normal pre-commit, commit-msg and pre-push checks passed without a bypass. Publication validation and CLI TypeScript passed; plugin and JavaScript checks skipped unchanged paths. Independent committed writer review found no blockers. One guarded push succeeded; fresh API and SSH reads confirm the expected commit after initial API lag. No push retry occurred. - Replacement qualification and the full credential-execution review remain required before the single authorized full PR E2E. It remains unused. Historical OpenClaw resume failure remains unresolved. The old heartbeat stays paused. No workflow approval, retry, base replay or PR merge occurred. ### Advisor follow-up — `d3b11155f93f1b4ad9fefebd8eab7c6788d331b9` - Address both valid findings from [Advisor 36106765141](https://github.com/NVIDIA/NemoClaw/actions/runs/36106765141): inline the single-use selection reader and retain the preferred API in the documented recreation command. All nine specialists executed successfully; seven were clear. The prior native-model reuse finding was confirmed resolved. - The reader still uses recorded onboarding intent, validates the provider/model, leaves unreadable state unknown and removes its temporary download directory. No recreation decision, native configuration, credential handling, image input, assertion, budget or validator changes. - The owning inference page now explicitly selects Responses for recreation and gives the Chat Completions alternative. OpenClaw/Hermes scope and the replacement warning remain; Deep Agents Code is unchanged. Documentation build passed with zero errors and the two existing Fern warnings. - Parent `29594f6d74a565c3891f60b14b161bbb0b465634` passed [CI 36105487565](https://github.com/NVIDIA/NemoClaw/actions/runs/36105487565), including all 12 CLI shards, and [Images 36105487521](https://github.com/NVIDIA/NemoClaw/actions/runs/36105487521). All five image contracts, actual publication, three direct startup checks, staging QA and Docker/rootless Podman activation were verified. Both activation reports recorded 18 agent turns, no builds, and no cleanup failures. These results do not qualify this new follow-up. - Current CodeRabbit warnings were checked against the source: snapshot-commands tests native gateway configuration through fresh replacement, restore and clone; the old gateway-guard recovery test is removed. Pi receipt changes are the separately approved qualification repairs recorded below. The docstring percentage is advisory, not a demonstrated defect. - Isolated CLI/plugin builds, full CLI typecheck and 131 selected tests passed (88 focused CLI, 43 onboarding integration). The initial validation setup needed compiled outputs and disposable source revision metadata; no source or assertion was changed to address those prerequisites. Normal pre-commit, commit-msg and pre-push checks passed without bypass: publication validation and CLI TypeScript passed, while plugin and JavaScript checks skipped unchanged paths. The first commit hook pass formatted one argument list without changing its syntax structure or values. Independent committed review found no blockers. Current main `3a4eb285aee17d2c57ce991dc6fed93bad315d53` was fetched for comparison; no main integration was required. - Replacement CI, images and automated reviews must qualify this follow-up. The single full PR E2E remains undispatched; historical OpenClaw resume failure remains unresolved. The old heartbeat stays paused. No workflow approval, retry, base replay or PR merge occurred. ### Onboarding reuse and image-boundary repair — `29594f6d74a565c3891f60b14b161bbb0b465634` - Rerunning onboarding with the same recorded provider/model now preserves native OpenClaw edits. Explicit requested selection changes retain the existing confirmation/recreation flow. Missing or unreadable records remain unknown and do not turn native edits into a recreation trigger. Other agent, GPU, messaging, identity, backup and policy checks are unchanged. - Retain logical provider/model in the onboarding metadata record so later explicit changes can be detected. Do not copy native settings or credentials into that record. Plugin views still read native OpenClaw routing. The OpenClaw runtime-controls page documents this distinction; Hermes and Deep Agents Code behavior is unchanged. - Restore surviving built-image checks for packaged runner/snapshot imports, shell environment loading, writable plugin state, protected blueprint paths and command-failure propagation. These checks use synthetic values and existing disposable-container cleanup. The retired configuration guard/hash checks remain retired. - Both behavior regressions failed before repair. Isolated Linux Node.js 24.18.1 validation passed CLI/plugin builds, CLI typecheck and 162 selected tests (88 CLI, 43 onboarding integration, 31 plugin). All 18 repository checks, seven growth checks, shell mutation probes and semantic phase collection (101 tests across 79 files) passed. The live census remains 1,356 direct expectations across 78 files. No live assertion, timeout, budget, validator or policy was weakened. - Independent validation used canonical main `5871fcbcd7a6ae6043e947a32d469068b07a999e`, immutable validator dependencies and a credential-free, network-disabled container. All 83 installed packages in the validator dependency closure matched byte-for-byte. The existing JSON5 dependency remains; no main integration was needed. - `npm run docs` passed with zero errors and the existing Fern redirect-authentication and theme-contrast warnings. The macOS SQLite temporary-directory group failure reproduces with the unchanged exact-base implementation and is not repaired here. A phase-collection invocation through tsx failed in the host ESM loader; the native-Node command passed without changing source. - Normal pre-commit, commit-msg and pre-push checks passed without a bypass. The first commit-message check rejected an overlong line; its correction changed no source. Pre-push publication validation and CLI TypeScript passed; plugin and JavaScript-config checks skipped unchanged paths. Independent committed review passed with no blockers. All 72 PR commits are GitHub Verified. Replacement CI/images/Advisor remain pending. No secrets were added. - Parent `c6a7a71a8da262a3a95106ee628058ce78c196e5` passed [CI 36099345556](https://github.com/NVIDIA/NemoClaw/actions/runs/36099345556), [Images 36099345314](https://github.com/NVIDIA/NemoClaw/actions/runs/36099345314), and all nine specialists in [Advisor 36100443565](https://github.com/NVIDIA/NemoClaw/actions/runs/36100443565). Parent image contracts, digest publication and Docker/rootless Podman activation were verified. Those results do not qualify this new repair. - The earlier native-model reuse P1 is addressed by this repair, subject to replacement evaluation. Complete credential-execution review and one full PR E2E remain pending. Historical OpenClaw resume failure remains unresolved. The old heartbeat remains paused; no E2E dispatch, workflow approval, retry or PR merge occurred. ### Captured-state CI repair — `c6a7a71a8da262a3a95106ee628058ce78c196e5` - Repair the two PR-specific failure groups in [CI 36063202481](https://github.com/NVIDIA/NemoClaw/actions/runs/36063202481), preserving external merge `c1e735463a9ff61464cb4559d831a90064483a16`. No additional main merge was needed. - Captured stopped OpenClaw state now uses the CLI installation's JSON5 parser. Live sandbox inspection retains the image's parser. The child cannot resolve code from captured `node_modules`; existing bounded reads, file checks, empty environment, identity checks and redacted errors remain intact. - Regenerate stale aggregate E2E census values. The 48-count difference comes from the already-retired runtime override suite (46) and two configuration-hash checks. No live assertions, per-file budgets, validators or security policies change in this repair. Native-state persistence and main's stopped-state recovery evidence remain. - All 96 unique selected tests passed across completed runs, including the original failing rebuild scenario and seven captured-reader cases. All 18 repository checks, all seven growth checks, CLI build, full CLI typecheck, formatting and lint passed. Normal pre-commit, commit-msg and pre-push publication validation and CLI typecheck passed with SKIP unset; pre-push plugin and JavaScript checks skipped unchanged paths. Initial new tests reproduced the defect; four later matcher-class mistakes were corrected without changing product behavior. The first commit attempt stopped on branching in the new test and an outdated local main reference; splitting the cases and fetching the current reference resolved those checks without a merge or bypass. No full-suite pass is claimed. - The exact base `828324444336b8bd2fda30c9fc537f0612088ece` passed all 12 CLI shards and static checks in [CI 36062588717](https://github.com/NVIDIA/NemoClaw/actions/runs/36062588717). Its separate messaging image failure is not repaired here. - Independent writer `/root/docs_finish_12120` reviewed the repair, assertion dispositions and validation; existing stopped-state recovery documentation remains accurate. No secrets were added. - At that publication, the native-model onboarding reuse finding still needed a behavior decision. Fresh CI and current review evidence, image contract verification, and the complete credential-execution diff review remain required before full PR E2E. Historical OpenClaw resume failure remains unresolved. No E2E dispatch, workflow approval or retry has occurred under this repair. The old heartbeat is paused; the user's active finish-line goal replaces it. ### Pi receipt follow-up 9c2d770352 - Refresh both Pi qualification receipts from successful [Images run 36044833932](https://github.com/NVIDIA/NemoClaw/actions/runs/36044833932), built from `6683a1ecc448cfcc9ef0562dbc32040f7c8ddf02` in one workflow cohort. - Both architecture jobs executed image publication, digest validation, entrypoint validation and contract upload. Checked-in receipts match the original artifacts byte-for-byte. All Pi Dockerfile COPY inputs match the tested source; only the two receipts and their two authority hashes change. - All 18 repository checks passed without an exception, including the previously failing Pi receipt check. All 85 selected tests passed across isolated runs; CLI/plugin builds passed. Initial attempts lacked compiled plugin/catalog files and disposable Git revision metadata; correcting those test-environment prerequisites required no source or assertion edits. Normal pre-commit and commit-msg hooks passed. Normal pre-push publication validation and CLI TypeScript checks passed; plugin and JavaScript checks skipped unchanged paths. All 69 PR commits are GitHub Verified. - The one-time bootstrap exception is consumed. No validator, assertion, budget, image input or policy was changed by this follow-up. The diff contains no credentials. - On the bootstrap commit, all 12 CLI shards, package/typechecks, plugin tests and image activation checks passed. Static CI failed only for the receipts repaired here. A later gate-false CI run did not execute replacement tests. Advisor skipped after that failure; CodeRabbit remains paused at an older commit. These are not current review approvals. - Replacement CI and automated review remain required before the authorized full manual PR E2E. The historical OpenClaw resume health failure remains unresolved. - Monitoring resumed at the user's request; the single full PR E2E remains conditional and unconsumed. ### Conflict integration and Pi bootstrap — `6683a1ecc4` Merged main `0ceb8bde14f3f58d85d372551e49f652c5ee4a41` once into `d2f37a05b3810aa568888dabb9943e0a8249c25c` to resolve the Git conflicts. Both parents' history is retained. The later installer-only main commit `60200f44ec` merges cleanly in a read-only check; it was not integrated again. The lifecycle conflict retains main's locked transfer of abandoned published reservations and this PR's normalized native-selection display. The combined runtime bundle preserves native ownership and main's WeChat 2.4.9 pin. Its expected digest is updated without removing the integrity assertion. Main's plugin-provenance checks, installer behavior, run-directory diagnostics, tests and three documentation changes are retained. Existing assertion limits, timeouts and security policies are not weakened. Validation of the merged tree passed: 331 focused tests (158 CLI, 171 integration, two plugin), CLI/plugin builds, CLI and plugin production/test typechecks, and the live assertion census (1,356 expectations across 78 files). Tests ran in isolated Linux Node.js 24.18.1 without network, host credentials or Docker socket. `npm run docs` passed with zero Fern errors and two warnings, including generated variants and 69 guarded routes. These results do not establish a full-suite or live E2E pass. **Pi image qualification is pending.** Main changes Pi image inputs, so the existing a9 receipts fail source-parity validation. Under the [user-approved bootstrap exception](https://github.com/NVIDIA/NemoClaw/pull/12120#issuecomment-5820218108), this publication temporarily retains those records without claiming that they qualify the merged images. For this commit and push only, the aggregate `repository-checks` hook is skipped; all 17 non-Pi checks from its unchanged registry run separately against the reviewed tree. The only deferred result is `pi-qualification-receipt-refresh`. Other commit and publication hooks remain enabled. No validator, hook configuration, CI result or branch protection is changed. The follow-up must obtain both Pi artifacts from one successful run at this source revision, verify executed published-digest and entrypoint checks and unchanged Pi image inputs, then refresh the receipts and accepted hashes. Complete validation without the exception is required for that follow-up. This bootstrap is not merge approval or acceptance of stale qualification evidence. Independent writer `/root/docs_ci_repair_12120` reviewed conflict preservation, the bootstrap procedure, committed tree, validation and this complete PR text. The historical OpenClaw resume health failure remains unresolved. Monitoring stays paused; no full E2E run, manual workflow dispatch, retry or reviewer request was made. Historical evidence below applies only to its named revisions. ### Consolidated CI repair — `d2f37a05b3` This revision preserves external history through `a9a0fd974bad6dfcbcd49f33f438327186e26eb3` and repairs the five accepted CI groups. No additional main integration or E2E run was performed. Monitoring remains paused at the user's request. - Cover configured native-provider registration and absent-primary behavior in the compiled package test. - Lower stale source-architecture counts, mock the snapshot maintenance boundary with lifecycle assertions, and allocate gateway fixture ports through the operating system. - Reconcile startup tests resurrected by external merges with the accepted native-ownership contract. Remove obsolete tests for deleted baseline/recovery/hash helpers, retain all 11 authentication and step-down tests in a focused file, and repair the missing closing brace. The retained startup composition verifies native settings, unchanged retired hash state, no baseline creation, and gateway-token setup/export. It simulates root dispatch; it does not test real root capabilities. The startup file limit decreases from 4,256 to 3,377 lines. - Refresh both Pi qualification receipts and their accepted digests from [Images run 35957272054](https://github.com/NVIDIA/NemoClaw/actions/runs/35957272054), after separate user approval. Both artifacts identify a9 and one cohort. Both Pi jobs executed digest publication, published-digest validation and entrypoint checks successfully. The repair changes no Pi image inputs or qualification rules. Separate all-agent publication jobs skipped; this is not proof of completed all-agent publication. - No runtime logic, live E2E assertions, timeouts, security policies or cleanup behavior changed. No secrets were added. Validation passed across completed runs: 792 unique selected tests, one existing CLI skip, CLI/plugin builds and typechecks, source-shape and growth checks, Vitest project membership, full-PR mock parity, and the unchanged live assertion census (1,356 expectations across 78 files). Normal pre-commit and commit-msg hooks passed. The Pi receipt validator passed with byte-identical downloaded artifacts and unchanged image inputs. Tests ran in isolated Linux Node.js 24.18.1 with read-only dependencies, no network, host credentials or Docker socket, except the final 94-test startup rerun and seven growth checks on the host. Initial isolated attempts stopped on missing snapshot Git metadata, a read-only incremental cache, or missing generated build files. Those setup failures were corrected without changing product behavior. An initial source-string regression was removed after independent review; the final behavioral regression and source-shape check passed. Host doctor still reports its heap, Docker-memory and active-CLI limitations. No full repository test-suite pass is claimed. Independent writer `/root/docs_ci_repair_12120` reviewed the committed ten-file repair, external-history preservation, validation and this complete PR text. This increment needs no public documentation change; the PR's earlier documentation changes remain. Historical entries below describe their named commits, not qualification of this revision. Before this repair, all 13 issue comments, six reviews and four resolved threads were collected. CodeRabbit remains paused at 19ae303; Advisor 35958300401 skipped all seven jobs after failed CI and produced no artifacts. Neither provides current approval. Fresh CI, image checks and scheduled reviews must qualify d2f37a05b3. The historical OpenClaw resume replacement-gateway health failure remains unresolved, and the PR still needs its separately deferred main-conflict resolution. No merge approval or CI waiver is claimed. ### Main integration — `0e6b70e806` Merged main `11541cde94` once to resolve the merge conflict. The only manual resolution regenerates `ci/e2e-assertion-budget.json` from the merged tests: 1,356 expectations across 78 files. Existing per-file budgets are preserved; main contributes the deferred-onboarding test. No assertions, timeouts or policies were weakened. Isolated Linux Node.js 24.18.1 validation passed both builds, 522 selected tests, CLI/plugin typechecks, seven growth checks, the assertion census and full-PR semantic mock parity. The docs build, generated variants and route checks passed with zero errors and two Fern warnings. Normal pre-commit and commit-msg hooks passed with the tested tree unchanged. Current-main documentation commit `26922313bb` does not change the validation surface; a read-only merge check found no conflict. No second main integration or live E2E run was performed. Fresh CI, image activation and automated review must qualify this new commit. The earlier OpenClaw resume failure remains unresolved; passing Hermes evidence belongs to the previous diagnostic commit. ### Native routing and recovery reporting repair — 3f52494bd5 The latest repair addresses Kao's [routing-ownership finding](https://github.com/NVIDIA/NemoClaw/pull/12120#issuecomment-5786508276). Registration and status/onboard/config views read native OpenClaw configuration, not an onboarding route snapshot. OpenClaw's NemoClaw metadata now retains only profile and onboarding time. Missing native primary does not restore a stale model or credential default. Providers other than `inference` remain OpenClaw-owned. Credential values are not displayed. Other agents retain the snapshots used by their resume checks. Both rebuild failure paths now name the retained source sandbox, distinguish a verified stop from unverified stop or maintenance reconciliation, and give preservation and inspection guidance. This changes reporting, not lifecycle or cleanup behavior. The two owning OpenClaw documentation pages were updated. The latest [resume diagnostic run on ec0bcf8d80](https://github.com/NVIDIA/NemoClaw/actions/runs/35904282555) passed Hermes but again failed OpenClaw replacement-gateway health after restore and release. The container exited with code 1 without exposing an application error; the pre-stop probe reported unavailable execution. Main has recorded passes, including the PR's exact base, so this remains a suspected PR regression with an unresolved cause. This repair does not claim to fix that E2E failure. Hermes' earlier restoration failure did not reproduce. No further live run has been dispatched or authorized. Validation: isolated Linux Node.js 24.18.1 CLI/plugin builds, all 1,113 plugin tests, 196 targeted CLI tests, typechecks and the repository's separate lint lanes passed. With user approval, validators from canonical main `11541cde94ceb5fb96670628ed6ae18e3be76257` checked the full PR diff in isolation: all seven growth checks, live assertion census and semantic mock parity passed. The live census remains 1,344 direct expectations across 77 files. Documentation build and OpenClaw-only variant checks passed; Fern reports the existing contrast warning and unavailable authenticated redirect comparison. Normal pre-commit and commit-msg hooks passed with no source changes. Independent committed review of all 17 changed files and this PR note found no blocking findings. No dependency, live assertion, timeout, budget, policy or cleanup behavior change. No secrets were added. No main integration or further E2E was performed. Fresh CI, managed-image activation and automated review must qualify the published repair; it is not merge-ready. Normal pre-push publication validation and CLI/plugin TypeScript checks passed. All 60 published PR commits are GitHub Verified. ### MCP reload repair 559b209a58 - Pass the recorded gateway, workspace and TLS directory through OpenClaw MCP reload helpers and add, migration, restart and restoration callers, including partial-failure recovery. This removes reliance on mutable ambient selection. Other agents retain their existing reload behavior. - Preserve external merge e6ac9465e7 and its main parent 117ca54c71. This increment changes eight source/test files only; no E2E tests, timeouts, budgets or dependencies change. - Isolated CLI/plugin builds, all 140 selected tests across completed runs, CLI typecheck, focused lint and unchanged assertion census passed. One process-based test exceeded its existing five-second limit during concurrent commit checks; its file passed all 36 tests alone, with that test completing in 1.6 seconds. No timeout was changed. Normal pre-commit, commit-msg and pre-push checks passed. - Independent final documentation writer review found no issues; no-docs-needed for this increment. Fresh CI, managed-image activation and Advisor results are pending. The parent Docker activation failed during image transfer before startup; it was not retried. This MCP repair does not establish the causes of the two unresolved onboarding failures. ### Failure diagnostics a4aef09494 - Add bounded, redacted failure capture before cleanup for messaging onboarding and OpenClaw channel stop/start. Capture sandbox status, startup logs, file metadata and loopback health, but not native configuration contents. Failed diagnostics preserve the original failure. - Capture MCP distinct-call request metadata and server status without supplying the missing host secret or retrying the call. Existing assertions, timeouts, cleanup, production code and assertion budgets are unchanged. - Isolated CLI/plugin builds, 71 focused tests, focused lint and the unchanged assertion census passed. Normal commit and pre-push checks passed. Independent final documentation review found no issues; this test-only increment needs no new public documentation. - [E2E retry attempt 2](https://github.com/NVIDIA/NemoClaw/actions/runs/35787725622/attempts/2) still failed both onboarding tests. MCP passed the original distinct discovery assertion, then failed trusted-private route inspection. These results do not establish the onboarding causes or prove the MCP defect fixed. The next step is focused live reproduction after CI and images pass, not another full suite or main merge. ### Channel fixture repair e5d563bbe5 - Repaired both integration fixtures behind failed shards 6 and 12 in CI 35781460854. Fixtures now supply recorded runtime selection; the bridge simulation accepts the leading gateway option and verifies gateway, workspace, TLS path and environment replacement. Production targeting and missing-target refusal are unchanged. - All 61 channel integration tests and 28 gateway/removal CLI tests passed in isolated Node 24.18.1. Focused lint and normal pre-commit, commit-msg and pre-push hooks passed. No test timeout or production source changed. Independent final documentation review found no issues; no additional documentation is needed for this test-only increment. - The separate green CI 35781514555 skipped tests; it does not supersede the failed executed test run. New CI and image qualification must pass before the authorized full E2E. The two unresolved live onboarding failures still need new diagnostic evidence. ### Main integration 46bf6366ab - Merged main `c1a54f78d7f756a13397d7fba250c21af860315f`, including #12232 latency/Slack/Discord fixture repairs and preceding #12222 reviewed SDK installation for MCP E2E. Published history and all prior production repairs are preserved. No production source changed in this integration. - The only conflict was assertion-census metadata. Regenerated it for the combined tree: 77 test files, 1345 direct expectations, 2101 direct assertion points and 3339 unique points. All changed limits decrease; no removed PR test was restored. The other twelve integration files match the merged main commit exactly. - Isolated CLI/plugin builds, CLI typecheck, both complete lint passes, the census check and 162 selected tests passed. Normal pre-commit, commit-msg and pre-push hooks passed. Independent documentation review found no issues. The inherited E2E README update describes the merged fixtures; no additional documentation change was needed. The initial dispatch-test load needed a writable temporary compilation cache; no product change was needed. - #12232 addresses three historical baseline signatures, not the two unresolved initial-onboarding failures. #12222 repairs MCP test setup; live confirmation on this combined candidate remains required. No new full E2E or job retry has been dispatched for this merge. Current-commit CI, image qualification and scheduled review results are separate pending gates. ### Gateway sibling repair and onboarding diagnostics c1fda3d84d - Fix Kao's recorded-runtime omissions in tunnel-origin registration (including services start), OpenClaw web-search reuse, and direct channel config removal. Native reads, mutations and restart reuse the recorded gateway/workspace/TLS selection. Missing recorded targets do not fall back to ambient selection. Conflicting-ambient and missing-target tests protect the shared resolver and its three consumers. - Preserve bounded, redacted onboarding recovery/readiness failure details instead of discarding them when returning a boolean. This changes diagnostics only, not readiness acceptance, retry timing or cleanup. - [Full E2E 35772180677](https://github.com/NVIDIA/NemoClaw/actions/runs/35772180677) tested parent `595ac6ccfe` and completed with 64 successful jobs, 13 skipped jobs, 14 failed execution jobs and one failed aggregate. Twelve failure signatures also occur in [historical main baseline 35666828863](https://github.com/NVIDIA/NemoClaw/actions/runs/35666828863). Messaging onboarding and OpenClaw channel stop/start remain unresolved: they passed that baseline, but current artifacts lack the sandbox failure logs needed to establish cause. Cleanup succeeded and removed those resources. The new gateway repair is not claimed to fix either failure. Hermes rebuild/public reference, DCode and both legacy upgrades pass. - Isolated CLI/plugin builds, final CLI typecheck and both complete Oxlint passes passed. Across focused and adjacent batches, 258 unique tests passed. An unchanged adjacent command test hit a five-second cold-load timeout; its separate single-worker run with a 30-second execution allowance passed, with the first case taking four seconds. A new restart test's cold module load was moved outside its timed body, and its mock was corrected to the typed failure result; all 35 affected tests passed afterward. No source timeout or live assertion changed. - Validation used Node 24.18.1 Linux ARM64, trusted read-only validator dependencies, no network, host credentials or Docker socket, and canonical comparison refreshed from `aee49c20420aeb359470cd14a8d699239887c02e` to `c1a54f78d7f756a13397d7fba250c21af860315f`. The new main increment changes E2E fixtures, census metadata and their tests, not the compiler/lint/test-runner execution paths used here. The prior user-authorized isolated procedure covers the existing JSON5 manifest difference. No main integration occurred; merged #12232 addresses three historical baseline signatures but is not included in this candidate. - Normal pre-commit, commit-msg and pre-push passed. All PR commits are GitHub Verified. Independent documentation review found no issues; this increment needs no documentation changes. No secrets were added. - Parent CI and managed images passed. Advisor 35770684852 completed all nine specialists; its single-value-writer cleanup finding assumes one consumer, but tunnel and web-search are two production consumers. It is not an established P1 behavior defect. New-commit CI and scheduled reviews remain pending. No new E2E or job retry was dispatched for this increment. ### Assertion-budget repair 595ac6ccfe - Correct one metadata file after the external main merges restored main's E2E assertion budget while retaining this PR's pruned tests. No production code, test assertion, workflow, or validator changed. All changed limits decrease. - [CI 35764668656](https://github.com/NVIDIA/NemoClaw/actions/runs/35764668656) failed static checks and shard 9 for this same stale budget. The other 11 CLI shards passed. [Managed images and both activation jobs](https://github.com/NVIDIA/NemoClaw/actions/runs/35764668557), portable checks, and Code Quality passed for parent `39754531fc`. Advisor skipped because CI failed. - Regenerated using the canonical census tool: 77 test files, 1,349 direct expect calls, 2,108 direct assertion points, and 3,355 unique assertion points. The assertion check and all 13 census tests passed. - Validation ran in isolated Node 24.18.1 Linux ARM64 with trusted read-only dependencies, no network, and no host credentials or Docker socket. The census tool and execution paths match canonical main `c3b7666ac47caa2389286a3b260bf811ebd47007`. The existing user-authorized isolated procedure covers the JSON5 manifest difference. - Normal pre-commit, commit-msg, and pre-push passed. All PR commits are GitHub Verified. Independent final review found no issues; this metadata-only increment needs no documentation change. No secrets were added. - CI and managed-image checks passed. Full default mock E2E 35772180677 completed; see the latest comparison and remaining two unresolved outcomes above. ### CI repair 3a552bba30 - Repair both failures from [CI 35756809689](https://github.com/NVIDIA/NemoClaw/actions/runs/35756809689) in one forward commit. Extract OpenClaw requested selection handling without changing behavior or the complexity budget. Update the preflight assertion and cover explicit recorded gateway propagation. - Isolated validation passed: CLI/plugin builds, trusted CLI typecheck, both complete Oxlint passes (4,857 ordinary files and 257 type-aware files), and 61 selected tests. These include 31 selection-drift, 16 gateway-containment, 9 recreation, and 5 preflight cases. A test-cache ownership error was corrected in the container; no product change was needed. - Normal pre-commit, commit-msg, and pre-push hooks passed. All published commits are GitHub Verified. No secrets were added. - Validation used Node 24.18.1 Linux ARM64 with read-only dependencies and no network, host credentials, or Docker socket. The existing user-authorized isolated validation procedure covers the JSON5 manifest difference. Canonical main was refreshed to `9f9b15e38bb32720b74333e3ec468483038605aa`; its new router-health change does not alter the compiler, test-runner, or lint execution paths used here. No further main integration occurred. - Independent final review found no issues; this increment needs no documentation change. New CI and managed-image checks are pending. One new full default mock E2E is authorized after those checks pass; it has not yet been dispatched. ### Gateway-selection repair ba42dab204 - Fix the P1 confirmed by Kao and Advisor: inference configuration reads, native writes, restart, and pairing use the recorded gateway. MCP configuration reads, registration, and removal retain the full runtime selection. - Preserve main merge `07e11c7b66`, including Rebecca's merged #12177. Its DCode resolver and tests are unchanged by this repair; the older exact-base workaround is superseded by upstream input compatibility checks. - Add bounded, redacted output for a failed DCode connection probe without changing the live assertion or retry policy. - Isolated validation: CLI/plugin builds and trusted CLI typecheck passed. All 396 selected CLI tests and 53 redaction tests passed. The two shell integration files passed 12/12 after supplying jq and running as a non-root user. This is 461 unique passing tests across runs, not one aggregate run. - Normal pre-commit, commit-msg, and pre-push hooks passed. All PR commits are GitHub Verified. No secrets were added. - Validation used Node 24.18.1 Linux ARM64, read-only dependency mounts, trusted compiler/test-runner entry points, and no host credentials or Docker socket. Canonical comparison: `2d0b130925663e98da3479afa2b5d40930b3356a`. The existing user-authorized isolated procedure covers the JSON5 manifest difference. Initial setup failures involved missing build artifacts, a read-only compilation cache, missing jq, and a root-only fixture mismatch; no product edits were needed for these. - Image checks passed for ba42dab204. CI reported the two failures repaired above. No full E2E was dispatched for ba42dab204. The last full run, [35694263141](https://github.com/NVIDIA/NemoClaw/actions/runs/35694263141), had 13 failures matching the recorded main baseline and five unresolved failures. This commit does not claim to resolve all five. ### Consolidated repair fd8eea4afb - Fix the two Advisor findings from [run 35680920357](https://github.com/NVIDIA/NemoClaw/actions/runs/35680920357): WeChat hook config writes now use native OpenClaw patching; clone restores hold the gateway down through state restoration and native startup. - Fix the confirmed v0.0.123 upgrade regression from [E2E run 35682526610](https://github.com/NVIDIA/NemoClaw/actions/runs/35682526610): remove only the empty legacy exec-approvals placeholder before OpenClaw migration. Preserve nonempty files and reject unsafe links or directories. - Fix the independently reviewed sub-agent credential recipe: install as the sandbox user with a random mode-0600 temporary file and fail-safe cleanup. - Isolated Linux validation passed: CLI/plugin builds; trusted CLI type-check; 184 focused tests with 1 existing skip; changed-file lint; documentation build with 0 errors and 2 warnings. After a test-only refactor, the affected 44 tests passed again with 1 skip. All 7 growth checks passed. - Credential-recipe Linux checks passed for a new private file, replacement of a symlink destination without changing its target, and rejection of a directory destination with temporary-file cleanup. - Validation caveats: one root-user Slack warning test fails identically on trusted main and passes as a normal user. A snapshot import timeout under parallel load passed on an unchanged isolated rerun. Neither required a product change. - Trusted validation base: efea304745bba80035067ba28898e3eb62409ec6. Candidate tree: 47b5ea6539aed2a7a9776205956fe4beb01e533c. User-authorized isolated validation used Node 24.18.1 Linux ARM64 image sha256:19cd848a0e073d34bd8cd5545a1b6b4d28489b3e3b607366621ced442bd5f6b4, no host credentials or Docker socket, and byte-verified validator packages. The CLI compiler ran from the trusted dependency tree. - Normal commit and pre-push hooks passed, including the secret scan. All PR commits are GitHub Verified. - CI and image checks passed for fd8eea4. Full E2E [35694263141](https://github.com/NVIDIA/NemoClaw/actions/runs/35694263141) completed: the legacy upgrade test passed; 13 failures matched [main baseline 35666828863](https://github.com/NVIDIA/NemoClaw/actions/runs/35666828863), and five remained unresolved. See the latest repair section above. ### Earlier validation - `npm run build:cli` — passed. - `npx vitest run --project package-contract test/package-contract/openshell-policy-boundary.test.ts test/package-contract/openshell-sdk-loading.test.ts` — passed (16 tests). - `NODE_OPTIONS=--max-old-space-size=8192 npm run typecheck:cli` — passed. - `npm --prefix nemoclaw run typecheck` — passed. - Focused CLI, integration, OpenClaw runtime, inference, MCP, tunnel, onboarding, and E2E-support suites — passed. - Focused CI cleanup suites — passed: providerless configuration (33), doctor and workflow inventory (76), sandbox marker contracts (79), runtime environment (7), snapshot restore (1), and growth guardrails (7). - `npm --prefix tools/mcp-tool-discovery-runtime run bundle:reviewed:check` — passed. - `npm run e2e:assertions:check` — passed with 1,401 direct assertions across 78 files. - `npm run source-shape:check` — passed. - Codebase growth guardrails — passed. - `npm run docs` — passed with 0 errors and 2 pre-existing warnings. - Clean-checkout local documentation link validation — passed for all 219 source documents. - `git diff --check origin/main...HEAD` — passed. - `npm run checks:repository` — passed, including the Pi qualification receipt refresh gate. - Pi candidate qualification — Linux AMD64 and ARM64 passed in [workflow run 35521490318](https://github.com/NVIDIA/NemoClaw/actions/runs/35521490318); the checked-in receipts are byte-identical to its artifacts. - `npx tsx scripts/checks/e2e-mock-parity.mts --base origin/main --head HEAD` — passed; each changed live E2E maps to a changed fast test. - GitHub commit verification — all PR commits are Verified, including final head b76671100121c2438d74cb0a946f4a6e084a1d13. - Secret scan — passed; the diff contains no secrets, API keys, or credentials. - Review-gap repair commit `51512b7d57ae42d18cb9c1d4f6f4566a716462a9`, CodeQL fix-forward commit `2e4091e389c59477082aad094f665a420809c304`, final Advisor repair commit `92a1a56022d808f9f262b07d1e2059e046edd395`, and reuse reconciliation repair commit `e59cf5ee790d431f79d718ee04af987a5a6fb348` are GitHub `Verified`; normal commit and pre-push hooks passed. - Final Advisor repairs use one atomic native OpenClaw config batch, return a nonzero result with same-command retry guidance when completion is unconfirmed, rotate restored redaction-marker gateway tokens, and remove onboarding config validation as a residual host veto. - Final focused validation passed (66 tests), plus CLI type checking, Oxlint, ShellCheck, all 18 repository checks, growth guardrails, and documentation build with 0 errors. `npm run test:changed` reached 1,601 passes and 2 skips; four unrelated snapshot auto-create tests stopped before their mocks at the local OpenShell Homebrew trust preflight. - CodeQL URL-membership findings were resolved with exact array-element equality; fresh JavaScript/TypeScript CodeQL and the aggregate CodeQL check passed on final head `2e4091e389c59477082aad094f665a420809c304`. Semantic phase coverage, repository checks, and the 1,401-assertion ratchet remained green. - `npx vitest run --project integration test/agents/openclaw/runtime/nemoclaw-start.test.ts` — passed (104 tests). - Focused E2E-support validation — passed (13 tests); semantic E2E phase coverage, the 1,401-assertion ratchet, exact Vitest project membership, and all 18 repository checks passed. - Published-head E2E [run 35529797029](https://github.com/NVIDIA/NemoClaw/actions/runs/35529797029): state backup/restore, rebuild, and inference switch passed; `full-e2e` exposed a test defect where timeout setup was conditional but its assertion was unconditional. - Exact-base replay [run 35530458283](https://github.com/NVIDIA/NemoClaw/actions/runs/35530458283): the same three targets passed; `full-e2e` failed later on a transient npm registry lookup, so the formal comparison remains unresolved rather than a candidate regression. - Fixed-head E2E [run 35532900168](https://github.com/NVIDIA/NemoClaw/actions/runs/35532900168) stopped before candidate execution because the exact-head managed-image publication was still building; no E2E test ran in that attempt. - Final exact-head E2E [run 35541175312](https://github.com/NVIDIA/NemoClaw/actions/runs/35541175312): full OpenClaw, snapshot restore, OpenClaw rebuild, and inference switching all passed on `e59cf5ee790d431f79d718ee04af987a5a6fb348`. - Consolidated Advisor and independent-audit repair commit `9a875be83c7caa952a864d2eab635336e6e42ffd` is GitHub `Verified`. `npm run validate:pr` passed; all 27 changed test files passed (647 tests), the final focused follow-up passed (70 tests), both TypeScript checks passed, all 18 repository checks passed, and `npm run docs` passed with 0 errors. - The independent P0/P1 audit found no remaining blockers across input validation, authorization, secret exposure, injection, cryptography, dependencies, state integrity, race handling, and error handling. It additionally closed JSON5 ownership gaps in restored-session reconciliation, web-search verification, and dashboard token retrieval. - Final E2E diagnosis compared candidate [run 35550078289](https://github.com/NVIDIA/NemoClaw/actions/runs/35550078289) with exact-base [run 35551184293](https://github.com/NVIDIA/NemoClaw/actions/runs/35551184293). Four OpenClaw product-path failures passed on the base and shared one cause: the pruned runtime normalizer exposed image defaults of `2770`/`0660`. Final commit `81e0fdd5e20ecf237d39910cc43042353e59ecef` provisions native `0700`/`0600` modes for sandbox-user images while retaining shared modes for root-mode images. - Two GPU candidate/base mismatches failed before exercising the changed OpenClaw path because the runner lacked an Ollama service or binary and gateway registration; no PR fix was appropriate. All other candidate failures reproduced on the exact base. - Final validation passed: 86 focused tests, 7 growth-guardrail tests, all 18 repository checks, CLI type checking, Oxfmt, hadolint, secret scan, and documentation validation with 0 errors. The stale JSON5 parse-error assertion that failed CLI shard 10 was corrected in the same commit. Normal commit and pre-push hooks passed, and the final commit is GitHub `Verified`. - Final publication reconciliation: `658c37cf75642694f37ec86159860588cbae06be` regenerated the shared runtime bundle, and fix-forward `431299a582a6369b2f3f685b8e995a6f0ad19dce` restored the unconsumed shared state declaration and bundle byte-for-byte to avoid unrelated Pi requalification. The final tree keeps only the Dockerfile permission behavior, its focused test, documentation, and the JSON5 assertion repair. All 18 repository checks, reviewed-bundle verification, and normal pre-push validation passed; both commits are GitHub `Verified`. - Final dashboard-bind contract repair `38df426a702735c07d940f3cd4deda12d062466d` allowlists the exact reviewed permission-only Dockerfile instruction. The focused lifecycle suite passed (28 tests), all 18 repository checks passed, normal pre-push validation passed, and the commit is GitHub `Verified`. - Native-selection and JSON5 snapshot repair commit 3f71b83d2b24e36e3e7291558f2263fb384dac6d is GitHub Verified. OpenClaw drift detection now reads only the native model scalar inside the sandbox, validates bounded control-free identities, and compares and displays the API-specific native target. Snapshot sanitization serializes native JSON5 as standard JSON so comments cannot retain credentials. Focused selection, lifecycle, credential-filter, and snapshot tests passed; one unrelated 5-second timeout under parallel load passed on isolated rerun (31/31). CLI type checking, all 18 repository checks, formatting, diff checks, the documentation build, normal commit hooks, and pre-push publication validation passed. - CI fixture fix-forward commit 0ab6c220a1a1bc9d325653d4ea5c690e0540cdfe is GitHub Verified. It updates the two interactive onboarding fixtures to return the native OpenClaw model scalar instead of relying on the retired selection-file download. The targeted scenarios passed, the full recreation file passed 9/9, focused CLI tests passed 77/77, CLI type checking and all 18 repository checks passed, and normal commit and pre-push hooks passed. - Final native-ownership repair commit `82de84914c770212eb4350de814276594933ebf1` is GitHub `Verified`. It removes the remaining post-launch model, API, and CORS writers and their obsolete live E2E lane; validates bounded OpenClaw JSON5 structure before recursive credential filtering; and documents fresh sandbox recreation for supported API changes. Focused CLI security/config/tunnel tests passed 82/82, integration startup/risk tests passed 307/307, and affected E2E-support tests passed 137/137. CLI type checking, all 18 repository checks, source-shape checks, growth guardrails, documentation validation, normal commit hooks, and pre-push publication validation passed. - Package-contract fix-forward commit `0dd7fab6f5e4c416fddae3571194ef6540d39f6b` is GitHub `Verified`. It copies the new compiled config-structure dependency into both isolated package fixtures. The two formerly failing package-contract files pass 3/3; normal commit hooks and pre-push publication validation passed. - JSON5 restore-contract fix-forward commit `179fc8a1e31545d9970d0e6e694b29e8b3956c39` is GitHub `Verified`. The resolved agent manifest is now the source of truth for OpenClaw JSON5 parsing, and snapshot E2E verifies the native gateway origin and `openclaw config validate` after both source and clone restores. Focused config tests passed 125/125, CLI type checking passed, all 18 repository checks passed, growth guardrails passed 7/7, and the E2E assertion ratchet remained unchanged at 1,371 assertions across 77 files. Normal commit and pre-push hooks passed. - Exact-head [Gate CI run 35568483238](https://github.com/NVIDIA/NemoClaw/actions/runs/35568483238) passed all build, typecheck, static, package, plugin, installer, and 12 CLI shard jobs. Final [Advisor run 35569442369](https://github.com/NVIDIA/NemoClaw/actions/runs/35569442369) passed all nine specialists and its no-blocker gate. No further E2E dispatch was recommended. - Shard-5 and Kao review repair commit `efa2833c9cbbb2bd7fb69b0979b042016494b7bd` is GitHub `Verified`. The stale rebuild lifecycle mocks now match the unregistered recovery API. Native OpenClaw values use a mode-`0600` temporary `--batch-file`, and inference switching updates only the selected agent model path instead of resending the full roster. Focused validation passed 73/73 tests; CLI type checking, all 18 repository checks, normal commit hooks, and pre-push validation passed. - Current-main integration commit `ad0e18d698d515b9ba7454be24b8b4dfad4a4c26` is GitHub `Verified`. It cleanly merges `cf9f9157e58238ec3a0503186beb44f75655e976` without changing the repair blobs. Focused validation passed 73/73 tests; CLI type checking, all 18 repository checks, diff checks, and normal pre-push validation passed. - Managed-image race fix-forward `b76671100121c2438d74cb0a946f4a6e084a1d13` is GitHub `Verified`. It rejects a Deep Agents registry base whose source revision differs from the PR base and builds the exact candidate base locally. This prevents an older main publication run from overwriting `latest` with incompatible contents. The resolver and full managed-image workflow contract suites passed 38/38; CLI type checking, ShellCheck, all 18 repository checks, normal commit hooks, and pre-push validation passed. ## Review notes The committed candidate review is recorded above. The following paragraphs describe earlier named revisions, not qualification of this candidate. The latest three-file follow-up prevents diagnostic log truncation from retaining credential fragments. Independent writer `/root/docs_finish_12120` reviewed the committed repair, validation evidence and complete PR description and found no blockers. The preceding six-file repair restored root authentication setup and corrected credential-retention guidance. The broader full-PR credential review remains incomplete. This is not approval to merge. For `6683a1ecc4`, the only publication exception is the [recorded Pi receipt bootstrap](https://github.com/NVIDIA/NemoClaw/pull/12120#issuecomment-5820218108). The authenticated account had MAINTAIN permission; Codex recorded the explicit user approval and verified comment readback. The bootstrap remains unqualified and cannot support merge approval. Independent review found no additional conflict-preservation defect. The following paragraphs retain earlier revisions' review context. Independent writer `/root/docs_gateway_siblings` reviewed the merge integration and documentation overlaps. All files except the census resolution match Git's automatic merge; prior PR repairs and main's behavior are preserved. This is an integration review, not a fresh audit of every upstream feature. No CI waiver, E2E success or merge approval is claimed. For `3f52494bd513e88b7ddf287f765e8c27c62586ab`, self-review covered native provider/model/credential ownership, missing-primary behavior, URL and credential redaction, sibling consumers, and retained-source recovery reporting. Independent documentation writer `/root/docs_gateway_siblings` reviewed the committed 17-file increment and PR note with no blocking findings. The two owning OpenClaw pages were updated and built. The user approved isolated validation with canonical-main validators and guarded publication without main integration or another E2E. OpenClaw resume remains unresolved; no CI waiver or merge approval is claimed. For `c1fda3d84d`, self-review covered the complete native-configuration repair, selected credential environment, failure propagation, and redacted diagnostics. Independent documentation writer `/root/docs_gateway_siblings` reviewed the final increment with no findings. No new dependency, cryptography, workflow or live retry was introduced. The two onboarding E2E root causes remain unresolved; this is not merge approval. For `3a552bba30`, self-review and independent review covered the complete two-file repair and surrounding selection handling. No findings; full E2E and automated review remain pending. This is not merge approval. For `ba42dab204`, self-review covered recorded-gateway selection, conflicting ambient selectors, MCP add/remove, read-before-mutation, and restart/pairing. Independent documentation reviewer `/root/review_gateway_forward` reviewed the final commit and found no blocking findings. Sensitive native configuration and E2E diagnostics still require the new CI and automated-review results; this is not merge approval. The final receipt commit records both Pi candidates produced from implementation head `13ab1b0515b3442c3a190767e8cecc440be2195d` in one workflow cohort. The final push passed the normal publication validation without a bypass. This supersedes the selective heartbeat merge proposed by #10748; native ownership preserves the complete credential-sanitized configuration instead of extending the former allowlist. <!-- nemoclaw-docs-review:start --> - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: Reviewed the complete PR documentation and the final two-file CI correction. Verified that the retired `runtime-overrides` workflow job no longer references its deleted live test, the surviving managed-image job owns the required YAML anchors, and the exact reusable-workflow inventory matches. This CI-only correction needs no additional user documentation. Focused validation passed 121/121 tests, all 18 repository checks passed, YAML parsing and diff checks passed, and normal commit and pre-push hooks passed. - Agent: `Codex Desktop /root/docs_review_pr12120_final` <!-- docs-review-base-sha: 4c44f7cc8103453b48ae49eac3c7e630ffe299e4 --> <!-- docs-review-commit-sha: f771a9bbe97054b70bd95f2e4f539593d5b26770 --> <!-- docs-review-tree-sha: 2834e2c72f75d2cdb080a4e702adca…
Summary
mcp-bridgelane depend on the run-scoped reviewed OpenShell SDK artifactWhy
Exact-head MCP E2E for #12181 reached the SDK-backed corporate-CA stop and failed with
ERR_MODULE_NOT_FOUNDfor@nvidia/openshell-sdk. The trusted workflow produced the reviewed SDK artifact but never installed it in the stablemcp-bridgejob. Candidate code cannot repair a trusted-workflow omission.Validation
npm run validate:prpassed from the clean committed treeFollow-up
After this workflow fix is available on
main, rerun the exact #12181 head with the stablemcp-bridgeselector and inspect every artifact before moving #12181 out of draft.Signed-off-by: Deepak Jain deepujain@gmail.com
Summary by CodeRabbit
Bug Fixes
Tests