Skip to content

test(e2e): verify public installer gateway trust - #12335

Merged
ericksoa merged 4 commits into
mainfrom
codex/fix-private-mcp-tls
Sep 25, 2026
Merged

ericksoa merged 4 commits into
mainfrom
codex/fix-private-mcp-tls

Conversation

@ericksoa

@ericksoa ericksoa commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Outcome

The public-installer workspace now has regression tests against the SDK's actual credential-state trust checks. A private workspace is accepted; a workspace with a writable ancestor is rejected before connection.

Reason

The cloud-onboarding fixture previously placed its isolated HOME beneath a temporary directory that the SDK rejects. PR #12181 already moved that workspace beneath the account home and landed the corporate-CA supervisor refresh. These tests verify the workspace correction at its consuming security boundary.

Related issues

Refs #12181. The production CA fix is already on main; this PR adds test coverage only.

Changes

  • Exercise the existing public-install workspace through the real SDK connection preflight, using inert test certificates and a fake connector.
  • Check acceptance of private ancestors, rejection of writable ancestors, and registered cleanup.

Verification

  • vitest run --project e2e-support test/e2e/support/corporate-ca-workload-kind.test.ts test/e2e/support/e2e-cleanup-resources.test.ts — 22 tests passed.
  • Normal publication validation and CLI type check — passed.
  • Signed commit hooks — passed on 4c39abfea596e37471a1a5e65e93bfe6953be096.
  • No network connection, real credentials, or runtime sandbox is used by these tests. No secrets, API keys, or credentials were added.
  • Exact-head CI 36171550759 passed; CodeRabbit reported no actionable findings; all nine specialists in Advisor run 36173182301 reported clear.
  • Selected branch E2E 36171734436, attempt 1, used candidate/controller 4c39abf, canonical base 7d02fef, its published image cohort, and OpenShell 0.0.116. This was 10 selected cases, not full unfiltered E2E: 6 passed and 4 failed.
  • Private TLS passed in all six MCP agent/runtime combinations, with completed HTTP requests and zero recorded TLS errors. The complete OpenClaw and Deep Agents MCP cases passed on Docker and Podman; both credential-generation controls passed.
  • Both Hermes cases failed later during replacement-credential gateway restart (health timeout / MCP configuration not reloaded). Bridge cleanup could not contact the sandbox, but final owned-sandbox deletion and destruction succeeded.
  • Both public cloud installers/onboarders exited 0, then failed the existing assertion that successful onboarding removes legacy credentials.json. The full cloud-onboarding cases remain failing.
  • Production code and live fixtures are identical to canonical base 7d02fef. The remaining runtime failures do not originate in this support-test-only diff. This does not establish that main is fully green or that all original 27 Podman failures are resolved.
  • All 10 case artifact archives were checked against their GitHub SHA-256 digests. Earlier candidate results are not used to qualify this revision.

Signed-off-by: Aaron Erickson aerickson@nvidia.com

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@ericksoa ericksoa self-assigned this Sep 25, 2026
@copy-pr-bot

copy-pr-bot Bot commented Sep 25, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: ef83b983-109a-4c62-8cf6-12bdb082882c

📥 Commits

Reviewing files that changed from the base of the PR and between 7d02fef and 4c39abf.

📒 Files selected for processing (1)
  • test/e2e/support/corporate-ca-workload-kind.test.ts

Included review availability: Your plan provides up to 12 included reviews per hour; 10 remain after this review.


📝 Walkthrough

Walkthrough

The change adds parameterized tests for connectManagedOpenShellSdk with private and writable workspace homes. The tests check connector calls, rejection text, and fixture cleanup.

Changes

Managed SDK workspace permissions

Layer / File(s) Summary
Workspace permission test coverage
test/e2e/support/corporate-ca-workload-kind.test.ts
The test checks that a 0700 workspace is accepted and that a 0777 workspace is rejected without calling the connector. Both cases verify fixture cleanup.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Suggested reviewers: aasthajh, afourniernv

Merge Risk: ⚪ Minimal · up to 4c39a

The new test covers rejection of a writable workspace ancestor, and no merge-blocking issue was identified.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 28.57% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 14 functions across 7 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the added end-to-end coverage for public-installer gateway trust.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@ericksoa

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Full review finished.

@github-code-quality

github-code-quality Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 4c39abf in the codex/fix-private-mc... branch remains at 96%, unchanged from commit 7d02fef in the main branch.

TypeScript / code-coverage/cli

The overall line coverage in commit 4c39abf in the codex/fix-private-mc... branch remains at 84%, unchanged from commit 7d02fef in the main branch.

Show a line coverage summary of the most impacted files.
File main 7d02fef codex/fix-private-mc... 4c39abf +/-
src/lib/agent/m...fest-readers.ts 97% 97% 0%
src/lib/agent/defs.ts 97% 97% 0%
src/lib/agent/s...-integration.ts 100% 100% 0%
src/lib/onboard...age/contract.ts 97% 98% +1%
src/lib/agent/s...ory-contract.ts 96% 97% +1%
src/lib/security/redact-url.ts 99% 100% +1%
src/lib/messagi...nnels/policy.ts 97% 98% +1%
src/lib/agent/dashboard-ui.ts 91% 94% +3%
src/lib/onboard...ay/state-dir.ts 83% 87% +4%
src/lib/adapter...penshell/sdk.ts 77% 89% +12%

Updated September 25, 2026 18:23 UTC

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@ericksoa

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Full review finished.

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@ericksoa ericksoa changed the title fix(onboard): refresh supervisor trust after corporate CA installation test(e2e): verify public installer gateway trust Sep 25, 2026
@ericksoa

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Full review finished.

@github-actions

Copy link
Copy Markdown
Contributor

PR Review Advisor finished for commit 4c39abf. Include the Advisor findings in the complete PR feedback collection. Verify and group valid findings before repair.

Request review only when Require no Advisor blockers is green.

All previous runs

@ericksoa
ericksoa marked this pull request as ready for review September 25, 2026 18:40
@ericksoa
ericksoa merged commit f3282ba into main Sep 25, 2026
146 of 151 checks passed
@ericksoa
ericksoa deleted the codex/fix-private-mcp-tls branch September 25, 2026 19:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant