Skip to content

chore(deps): trust OpenClaw 2026.9.5 manifests - #12380

Draft
nvidia-nemopatch-writer[bot] wants to merge 20 commits into
mainfrom
nemopatch/openclaw-upgrade/ddb54e135216a516/trust
Draft

nvidia-nemopatch-writer[bot] wants to merge 20 commits into
mainfrom
nemopatch/openclaw-upgrade/ddb54e135216a516/trust

Conversation

@nvidia-nemopatch-writer

@nvidia-nemopatch-writer nvidia-nemopatch-writer Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Outcome

Adds reviewed OpenClaw 2026.9.5 archive and replacement-graph identities while preserving the selected 2026.9.2 runtime and its existing trust entries.

Reason

The runtime migration in #12382 needs verified package identities and a reviewed replacement graph before selecting 2026.9.5. This PR stages that policy without changing the production runtime.

Changes

  • Preserve current runtime identities and security overrides; add the 2026.9.5 runtime, official channels (including Google Chat), Brave, Tavily, and diagnostics archives.
  • Bind the replacement runtime graph to the actual 2026.9.5 lockfile digest and exercise the checked-in policy with that lock fixture.
  • Document the staged transition, its removal condition, and the existing candidate-owned audit boundary accurately.
  • Record genuine AMD64 and ARM64 Pi receipts from run 37676667241, with exact artifact digests bound by the existing authority check.

Verification

  • Current candidate: 791f72b6d902eb7bc7d99fe988705024ce750b29, including the merged SDK prerequisite fix(e2e): install the locked SDK from reviewed archive bundles #12765.
  • Core CI and managed-image publication passed on this candidate. Docker and rootless Podman activation each completed 28 agent turns, all 13 phases and all 13 cleanup checks.
  • Genuine AMD64 and ARM64 Pi receipts from source 9abef33ddf73105c8f3f952ced9ce4eb53252126 remain valid: all Pi Dockerfile and COPY inputs are unchanged. Signed commit and publication hooks passed with every normal gate enabled.
  • The staged 2026.9.5 lock also matches the retained genuine CI audit artifact, produced from runtime source 3f7689e52945e5ddd1e0b67b5ede65edd232c87e. Its lock hash matches the trust policy and decompressed fixture: b73ebd8bb5e15cfcf080a21beaca0dce50cbca903988b20be74d49c9498baeb7. It reports zero high or critical advisories and three moderate advisories; the audit completed signature verification. This receipt expires on 2026-10-08 at 10:15:25 UTC.
  • Full manual E2E 37704093648, attempt 1, completed against trusted controller 1828f2ab1d4685c876261e2ec812d91bcfbe2df0 and this exact candidate: 73 successful jobs, nine leaf failures, one dependent aggregate failure, and 15 skipped jobs. It included all default jobs and the authorized staging Brev Launchable job. The prior base-image lookup blocker was fixed by merged fix(e2e): avoid workflow run pagination cap #12790.
  • 32 focused SDK and dependency-preparation tests passed during the preceding integration; that is historical supporting evidence.
  • The diff contains no secrets, API keys, or credentials.

Full E2E findings

The GPU/local-inference lane passed all nine OpenClaw, Hermes, and Deep Agents Code combinations across Ollama, vLLM, and NIM, plus three rollback scenarios and cleanup. Its retained artifact matches the published digest.

Five failed jobs also fail on main baseline run 37701046910: Pi reports native-inference connection errors; OpenClaw native switching rejects the fixture credential/endpoint combination with HTTP 401; Hermes deferred onboarding, Hermes native switching, and Launchable fail native sandbox inference with status 56. Launchable image selection, source provenance, build, and gateway startup passed in both runs. The owned Brev workspaces were deleted and independently verified absent.

The OpenClaw and Hermes Anthropic-switch jobs fail during test-module loading because their fixture sandbox names exceed the existing 19-character limit. The fixtures and validation source are identical to this PR's base.

Two failures remain unresolved: double onboarding cannot locate the sandbox container, and the credential-generation-window rebuild fails while quiescing the gateway. Both causal source paths are unchanged by this trust-policy PR, but both jobs passed in the compared main run; the retained diagnostics do not establish their underlying causes. These failures are not claimed as reproduced on main or cleared. Double-onboarding cleanup also lacks independent absence evidence after its raw deletion command.

All nine failed leaf-job logs and their available artifacts have been inspected; artifact digests were verified. Unreached assertions and skipped jobs supply no pass evidence. The full suite is not green, and no unchanged rerun has been dispatched.

Review notes

All nine specialists completed Advisor run 37697027151 with no blocking findings on this candidate. All findings, summaries and E2E recommendations were read. Required validation includes full E2E, Hermes E2E and Pi qualification.

This remains a draft. CI, managed images and Advisor are clear; full E2E has seven failures supported as shared issues and two lifecycle failures whose causes remain unresolved. E2E clearance is not claimed. CodeRabbit is deferred at the user's direction; no merge is authorized.


Signed-off-by: Prekshi Vyas prekshiv@nvidia.com

Patch-Walker-Manifest: sha256:8f02f4a58b35b10021a74ce9c687302a9955962b722a1eab2dd2cb2085b638a3
Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: d39aaf3f-c2ad-488a-bcb0-42d5800767f7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 791f72b in the nemopatch/openclaw-u... branch is 97%. The line coverage in commit 63002cd in the main branch is 96%.

Show a line coverage summary of the most impacted files.
File main 63002cd nemopatch/openclaw-u... 791f72b +/-
nemoclaw/src/onboard/config.ts 98% 96% -2%
nemoclaw/src/index.ts 94% 93% -1%
nemoclaw/src/bl...t-management.ts 100% 100% 0%
nemoclaw/src/co.../config-show.ts 100% 100% 0%
nemoclaw/src/commands/slash.ts 100% 100% 0%
nemoclaw/src/on...native-route.ts 0% 100% +100%

TypeScript / code-coverage/cli

The overall line coverage in commit 791f72b in the nemopatch/openclaw-u... branch is 85%. The line coverage in commit 63002cd in the main branch is 84%.

Show a line coverage summary of the most impacted files.
File main 63002cd nemopatch/openclaw-u... 791f72b +/-
src/lib/actions.../status-text.ts 84% 46% -38%
src/lib/state/sandbox.ts 92% 83% -9%
src/lib/onboard...al-inference.ts 84% 90% +6%
src/lib/policy/index.ts 71% 80% +9%
src/lib/state/p...l-retirement.ts 79% 92% +13%
src/lib/onboard.../application.ts 55% 72% +17%
src/lib/inferen...nvidia/index.ts 0% 85% +85%
src/lib/adapter...gnostics-cli.ts 0% 87% +87%
src/lib/onboard...ternal-image.ts 0% 91% +91%
src/lib/securit...ig-structure.ts 0% 98% +98%

Updated October 07, 2026 22:19 UTC

Patch-Walker-Manifest: sha256:0bc3b7783ef39fb636ddaff4a2769d9a18b29140fa835bfbdbef18d32be4285a
Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a
NemoPatch-Draft-Rebase: sha256:cc14a16725fe524469e3772b77626e607b690c4c239197456dfd2ee18807104e
Previous-Head: 149296d
Previous-Base: 3f98fc7
Previous-Action-Base: 241fcd1
Base-Commit: 4355902

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
nvidia-nemopatch-writer Bot pushed a commit that referenced this pull request Sep 28, 2026
Patch-Walker-Manifest: sha256:7b61075f19f9cce050ec27dd0dda884489d46621b635f33fd2950fb2428110c2
Prerequisite-PR: #12380
Prerequisite-Commit: 9972df9

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:aefb923570aafcfac1dbcdf63668265d81ce9b7edbc337468c1e7deb9ca18ff8
Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a
NemoPatch-Draft-Rebase: sha256:89cafad604a83e50b8537d3d3355d9300cb54e11f632f0ac50d732cbf730f9dc
Previous-Head: 9972df9
Previous-Base: 3f98fc7
Previous-Action-Base: 4355902
Base-Commit: 7e1310c

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
nvidia-nemopatch-writer Bot pushed a commit that referenced this pull request Sep 28, 2026
Patch-Walker-Manifest: sha256:4d7c1202834c4b68005ef21c866cfa0784f84eb1cde75f1adfad993a2d43aae3
Prerequisite-PR: #12380
Prerequisite-Commit: 4603d1d

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@prekshivyas
prekshivyas marked this pull request as ready for review September 29, 2026 02:25
@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@prekshivyas
prekshivyas marked this pull request as draft September 29, 2026 05:56
@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review skipped.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@wscurran wscurran added area: packaging Packages, images, registries, installers, or distribution area: security Security controls, permissions, secrets, or hardening integration: brave Brave integration behavior integration: discord Discord integration or channel behavior integration: openclaw OpenClaw integration behavior integration: slack Slack integration or channel behavior integration: whatsapp WhatsApp integration or channel behavior labels Oct 6, 2026
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Integrate the upstream SDK 1.31.0 repair and compaction safeguard.
Reconcile reviewed locks, offline archives, bundle assertions and fixtures.
Bind the replacement-lock fixture to the reviewed OpenClaw 9.5 graph.

User-approved Pi receipt deferral applies only to this bootstrap publication.
Genuine AMD64 and ARM64 qualification and the full gate remain required.

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor finished for commit f58db41. Include the Advisor findings in the complete PR feedback collection. Verify and group valid findings before repair.

Request review only when Require no Advisor blockers is green.

All previous runs

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: packaging Packages, images, registries, installers, or distribution area: security Security controls, permissions, secrets, or hardening integration: brave Brave integration behavior integration: discord Discord integration or channel behavior integration: openclaw OpenClaw integration behavior integration: slack Slack integration or channel behavior integration: whatsapp WhatsApp integration or channel behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants