…2847)
## Outcome
PR E2E uses the upgrade commit's reviewed dependency inputs instead of
forcing main's versions. This change consolidates #12848's Deep Agents
controller fix and extends candidate selection through protected CPU/GPU
image builds and the OpenShell host runtime.
The acceptance target is at most two PRs for upgrades to existing
supported dependencies: normally one upgrade PR, plus one
trust/bootstrap prerequisite when necessary. Ordinary version bumps must
not need a third workflow-fix PR.
## Reason
OpenShell #12603 needs candidate runtime qualification, and Deep Agents
#12376 needs its candidate base in the protected controller. Selecting
candidate artifacts only in ordinary jobs leaves protected consumers on
main's dependencies. Pi also needs to publish source before it can
attach the resulting qualification receipts.
## Changes
- Resolve a reviewed OpenShell release from fixed files at the candidate
commit. Run this resolver only for its selected gateway consumers.
Candidate source remains inert input to pin and operational-template
verification.
- Derive image prerequisites from the existing workflow dependency
graph. Gateway-only and native-producer selections do not wait for
unused image publication. Image consumers and full release qualification
retain their gates.
- Reuse the existing candidate image path for OpenClaw, Hermes, Deep
Agents, Pi, OpenShell and shared npm inputs. Published base reuse now
checks Dockerfiles, parser inputs, ignore rules and copied files for all
three managed agents.
- Build candidate OpenClaw, Hermes and Deep Agents bases on native CPU
runners. Export each as OCI content with its agent, source, workflow,
platform and run identity. Protected GPU consumers verify those bytes
and identities before offline use; they reject published-base
substitution for PR runs.
- Project only reviewed OpenShell modules and release literals into the
trusted GPU controller. Select the reviewed candidate SDK archive,
retain the trusted dependency graph, then build and verify the CLI.
Restore the seven projected source files after qualification. These
steps reuse existing pin, archive and dependency-resolution controls
because arbitrary candidate host code cannot run with protected
credentials.
- Reuse main's Pi `--publication` check for local source publication,
including later repairs in the same PR. The same PR then adds both
published receipts and matching authority. CI remains strict; partial
refreshes and source drift fail.
- Retain verified-byte receipt parsing, staging Launchable opt-in,
failure propagation, resource cleanup and full-release gates. Update the
owning E2E guidance.
- Refresh both Pi qualification receipts from the successful candidate
image publication. Correct the managed-base fixture's platform and
image-label inputs. Validate and read protected files through the same
descriptor, with symlink and hardlink rejection tests. Add fixed,
non-secret approval-selector failure categories without changing its
acceptance rules.
## Verification
Current commit: `da4ce1d219e538cab23cb519aa65e90fda55c8e7`; base:
`6a02aac7f0053978a20eaed73159386e0ad2aff9`.
- [Core CI](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126626)
passed, including all twelve CLI shards, coverage, static checks and the
final gate. [Security
scanning](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126621)
passed.
- [Managed-image publication and
activation](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126620)
passed. Both native Pi producers and all three managed-agent producers
succeeded. Docker and Podman artifacts bind the current commit and image
digests. Each reports 28 controlled-inference turns, zero activation
builds and 13 successful cleanup callbacks.
- [Self-hosted GPU
qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/37865127484)
passed on attempt 2. The initial selector timed out before managed
publication completed; one affected-job rerun after publication
succeeded passed selection and the live test. Verified evidence binds
`da4ce1d`, records full GPU offload, an authenticated real OpenClaw
agent turn, public runtime destruction and provider resources already
absent. All three cleanup callbacks passed.
- [Focused manual
qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/37869966568)
passed from trusted main, including Relevant E2E. All five selected jobs
passed: cloud onboarding, full OpenClaw E2E, Hermes E2E, and
OpenClaw/Hermes security posture. Verified artifacts bind the current PR
commit, workflow and dispatch correlation; each reports one passed test
with no failures, skips or errors. All recorded cleanup callbacks
passed. These tests do not establish candidate OpenShell 0.1.2 coverage.
Jetson, DGX Spark queue and staging Launchable opt-ins were false; full
Release qualification was not selected.
- Focused local validation of the expanded repair passed 13 files / 571
distinct tests. Projection tests cover immutable commits, reviewed
templates, SDK integrity, dependency metadata, tampering, filesystem
redirection, rollback and restoration. Executable SDK fixtures exercise
installation/import without lifecycle scripts or package credentials.
- Image handoff tests cover three agents and both native platforms. They
reject wrong-agent, source, workflow, run, platform and digest evidence.
Dependency-input regressions select candidate artifacts without workflow
edits and reject fallback to main after failed candidate publication.
- OpenShell #12603 package and lock inputs at
`f473315ca9b64cab56305f3bf4a15a877f0904b2` select reviewed SDK `0.1.2`
through the pure projector. This is not live SDK/runtime qualification.
- All four Pi checker/runner conflicts are resolved; those files match
the recorded main commit. The isolated checker/runner suite passed 57
tests. Normal commit hooks, isolated pre-push publication validation and
CLI TypeScript passed. All six PR commits are GitHub Verified.
- Local broad coverage could not finish under the approved macOS
isolation. The current Linux CI coverage result above supplies the
completed broad gate; no local broad-check pass or waiver is claimed.
- The diff contains no secrets, API keys or credentials.
## Review notes
Sensitive paths include `.github/workflows/e2e.yaml`, changed
`scripts/**`, `tools/e2e/**` and
`tools/pr-review-advisor/REVIEW-QUEUE.md`. Source self-review covers
candidate admission, protected execution, prerequisite propagation,
OCI/SDK verification and cleanup.
The [actual Advisor
run](https://github.com/NVIDIA/NemoClaw/actions/runs/37866718854)
reviewed current commit `da4ce1d` against base `6a02aac7`. All nine
specialists completed with no findings. Their artifacts and published
review were read. The deterministic E2E floor remains required; clear
reviews do not waive it.
[CodeRabbit's actual
review](#12847 (comment))
covers the final repair from `2cde38759` to `da4ce1d` and reports no
actionable comments. All three recorded review threads are resolved.
Earlier parity, receipt, fixture, pathname-race and diagnostic findings
were repaired; current core CI and security scanning passed afterward.
All reported PR checks and the focused manual E2E run are green on
`da4ce1d`. GitHub reports no merge conflicts, but human review remains
required. The protected qualification boundary below remains unresolved;
no automated review grants human approval or merge authority.
### Remaining qualification boundary
Current trusted main accepts only the v1 protected activation contract;
this PR introduces the v2 controller needed by candidate builds. Running
that known-rejected protected path before adoption would not qualify it.
Live protected candidate OpenShell/SDK projection therefore still needs
the adopted trusted controller, followed by testing the existing upgrade
PR. No third workflow PR should be needed for that supported path.
The completed Docker/Podman tests do not establish OpenShell 0.1.2
coverage or every dependency combination. Both current native Pi
publications and strict CI passed; Pi source publication and receipt
attachment remain within this PR. New release trust, SDK dependency
graphs, permissions or controller protocols may require the one allowed
trust/bootstrap prerequisite.
This PR does not claim full release qualification, waive missing
evidence, resolve the separate inference epic, or authorize merge.
---
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Reliability**
* E2E checks can skip managed-image publication when selected checks
don’t require those images, while still enforcing publication for
dependent checks.
* Protected runtime checks verify candidate image artifacts and use
reviewed OpenShell sources and SDK versions.
* Admin approval selection errors now produce specific diagnostics
without exposing sensitive details.
* **Compatibility**
* OpenShell gateway checks resolve the version from the selected
candidate rather than relying on a fixed version.
* **Documentation**
* Added guidance on managed-image handling, E2E prerequisites, and
protected runtime checks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Outcome
Upgrade managed LangChain Deep Agents Code from 0.1.55 to 0.1.71 with a hash-locked Python 3.13 dependency graph, updated startup and MCP behavior, and matching onboarding and runtime validation. Preserve the existing security, lifecycle, inference, and cleanup requirements.
Changes
Verification
Current signed, GitHub-verified head:
b32ea9e5a9b24df94fb4b76fe6ad793f2c482599. It refreshes both exact Pi qualification receipts and their repository-controlled SHA-256 authority from the same successful AMD64/ARM64 candidate run, without changing image inputs or the qualification guard. The exact-prior-head upstream SSH push passed normal publication validation and CLI typecheck. All 18 repository checks, 52 focused receipt tests, and normal signed commit hooks passed locally.Core CI on this head passed all 12 CLI shards, static checks, and the aggregate gate. The managed-image run passed both Pi candidate builds, all direct managed-image startup jobs, and exact-head Docker and rootless Podman activation. Each activation exercised OpenClaw, Hermes, and Deep Agents Code for 28 agent turns, including public lifecycle phases, with zero build commands and no cleanup failures. This managed run is separate from the full E2E suite.
The automatic nine-specialist Advisor review bound to this exact PR head and base reported no findings or extra E2E selectors; its no-blockers gate passed. The coordinator result is a read-only shadow recommendation, not an approval.
The last full manual PR E2E run on
d816e4fused the default target selection with Launchable opted out, no Jetson, and global mock inference; hosted catalogue profiles used actual NVIDIA inference. It finished with 75 successful, six failed, and 16 skipped leaf jobs, plus a failed aggregate gate. Hermes and OpenClaw native-switch stopped at credential-handle assertions repaired in later PR commits, but their later inference phases still need a full run. Pi native inference returned HTTP 401 on its first read task, matching a same-base main failure. Model Router could not discover its new direct sandbox container during onboarding; the next run has read-only discovery diagnostics. OpenClaw channel rebuild could not enter its gateway-down maintenance window, leaving later persistence phases unrun. These full-suite failures have not been cleared by the narrower managed run.The protected GPU/local-inference job stopped before GPU activation because trusted main projects the candidate gateway runtime but lacks its imported same-thread-group process reader (TS2307). Ready-for-review #12928 prepares that exact reader for trusted main and is still unmerged. The candidate-branch GPU success does not qualify the trusted-main-root run; no protected workflow or trust rule has been bypassed.
Remaining qualification
After the shared process reader is adopted into trusted main, rerun the full exact-head E2E selection and resolve or clearly classify every relevant failure with evidence. A skipped CodeRabbit check is not an actual review; the bot remains ineligible for this PR. No E2E failure, review, or main merge is waived.
Signed-off-by: Prekshi Vyas prekshiv@nvidia.com