Repository navigation
chore(deps): update OpenClaw to 2026.9.5 - #12382
nvidia-nemopatch-writer[bot] wants to merge 37 commits into
Conversation
Patch-Walker-Manifest: sha256:8f02f4a58b35b10021a74ce9c687302a9955962b722a1eab2dd2cb2085b638a3 Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:cd4ca477a440a48a39bd27315b6a6feab12ca9b047314adf5c60232a18166aa0 Patch-Walker-Action: sha256:d872c43b48b28bb23f8c5a815ed81a7e95e4c760673a4ae98919600b890a18c9 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall line coverage in commit 52a0fb1 in the Show a line coverage summary of the most impacted files.
TypeScript / code-coverage/cliThe overall line coverage in commit 52a0fb1 in the Show a line coverage summary of the most impacted files.
Updated |
Patch-Walker-Manifest: sha256:0bc3b7783ef39fb636ddaff4a2769d9a18b29140fa835bfbdbef18d32be4285a Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a NemoPatch-Draft-Rebase: sha256:cc14a16725fe524469e3772b77626e607b690c4c239197456dfd2ee18807104e Previous-Head: 149296d Previous-Base: 3f98fc7 Previous-Action-Base: 241fcd1 Base-Commit: 4355902 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:aefb923570aafcfac1dbcdf63668265d81ce9b7edbc337468c1e7deb9ca18ff8 Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a NemoPatch-Draft-Rebase: sha256:89cafad604a83e50b8537d3d3355d9300cb54e11f632f0ac50d732cbf730f9dc Previous-Head: 9972df9 Previous-Base: 3f98fc7 Previous-Action-Base: 4355902 Base-Commit: 7e1310c Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
@coderabbitai review |
|
@coderabbitai review |
|
@coderabbitai review |
|
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Integrate the upstream SDK 1.31.0 repair and compaction safeguard. Reconcile reviewed locks, offline archives, bundle assertions and fixtures. Resolve native SQLite proof temporary paths and group ownership on macOS. User-approved Pi receipt deferral applies only to this bootstrap publication. Genuine AMD64 and ARM64 qualification and the full gate remain required. Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
## Outcome Pi qualification can use immutable images whose source matches the checked-out candidate. The receipt/source check previously failed before onboarding because the recorded image source lacked the current reviewed npm audit input. ## Reason [Main E2E run 37556111817, attempt 2](https://github.com/NVIDIA/NemoClaw/actions/runs/37556111817/job/112596124337) tested `2306bc5f49c7a2f2697e9dfc781b5f4d21dc3580` against receipts from `545faaf4d3850e8cac9b84d3871e1f4330c26d03`. Among the selected Pi image inputs, `ci/reviewed-npm-audit.json` differs between those sources. ## Changes Refresh both architecture receipts from the successful trusted main [publication run 37552706149](https://github.com/NVIDIA/NemoClaw/actions/runs/37552706149), source `2306bc5f49c7a2f2697e9dfc781b5f4d21dc3580`, release `v0.1.0`, cohort `ghrun-37552706149-1`. Replace the two approved receipt hashes with the SHA-256 hashes of those exact artifact bytes. | Platform | Published digest | Publication job | Contract artifact | |---|---|---|---| | Linux AMD64 | `sha256:4388a19731121b2d715b7601ff9603eff73a108759d8c46c9b60d5f78e62c3b9` | [Publish and validate Pi candidate](https://github.com/NVIDIA/NemoClaw/actions/runs/37552706149/job/112575750811) | `11453458684` | | Linux ARM64 | `sha256:b7d0d5e0af771eff3e58fa169ac61ac63512e6177b9cfd78520005001df636e8` | [Publish and validate Pi candidate](https://github.com/NVIDIA/NemoClaw/actions/runs/37552706149/job/112575750866) | `11454073932` | The three-file diff preserves Pi candidate status, dependency versions, Linux AMD64/Docker qualification scope, NVIDIA hosted inference, image-input selection, and every qualification assertion. No receipt from #12382 is reused: its dependency-upgrade source and cohort differ. Open PRs were checked for a focused duplicate; #12396 adds supported-agent scope and #12382 changes dependencies. ## Verification Candidate: `14e10676ff003648ed03303338c487325d6b9e18`. - Existing candidate authority, qualified candidate, receipt refresh, runtime artifact, and qualification event tests: **5 files, 78 tests passed** (`vitest run --project cli --project integration --project e2e-support` with the five selected files). - `node --import tsx scripts/checks/pi-qualification-receipt-refresh.mts`: passed on the committed candidate. - Exact publication artifacts: archive SHA-256 values match GitHub metadata; both committed receipts equal their downloaded `contract.json` bytes. AMD64 archive `d6a029ac0328f64eeeb94e8cfcc96daa99799d47924c0facd18ced9dfb39d0e8`; ARM64 archive `f9d863f1a449bf6b2a88dd79d19ebab6ea5cd18f56fa6d08c34d8238fcca060c`. - Source parity: all 26 selected image paths match the publication source; the old source returns exit 1 and the refreshed source returns exit 0. - Assertion audit: 203 predicate rows traced through receipt validation, onboarding, all three read-tool scenarios, real PTY inference, native state, rebuild, restart recovery, security, evidence, and cleanup. Full runtime evidence passed on the exact final candidate; no assertions changed. - Normal pre-commit and commit-message hooks passed, including repository checks, secret scanning, and growth guardrails. Normal pre-push publication validation and all three compiler checks passed. - [PR CI](https://github.com/NVIDIA/NemoClaw/actions/runs/37568807736): passed. [Advisor](https://github.com/NVIDIA/NemoClaw/actions/runs/37570015246): all nine exact-head specialist reviews clear; blocker gate passed. - [Exact PR image prerequisite](https://github.com/NVIDIA/NemoClaw/actions/runs/37568807697): passed, including both native Pi architecture validations and Docker/rootless Podman activation. Its three shipped-agent contract archives were verified against artifact metadata and the exact PR head/cohort. - Focused trusted-main exact-head GitHub E2E (`jobs=pi-agent-qualification`, `gateway_runtimes=docker`, `inference_mode=public-nvidia`): **passed**: [workflow 37571476855](https://github.com/NVIDIA/NemoClaw/actions/runs/37571476855), [Pi target job](https://github.com/NVIDIA/NemoClaw/actions/runs/37571476855/job/112631856957), and [Relevant E2E gate](https://github.com/NVIDIA/NemoClaw/actions/runs/37571476855/job/112632788964). [The first dispatch](https://github.com/NVIDIA/NemoClaw/actions/runs/37568859569) stopped before planning because the exact PR image workflow was still running. Its full prerequisite and downstream logs were inspected; no Pi resources were created. The current run followed verified prerequisite success, with the candidate unchanged. - [Qualification evidence artifact 11460609789](https://github.com/NVIDIA/NemoClaw/actions/runs/37571476855/artifacts/11460609789): exact CLI/image/source/cohort/receipt identity; receipt/source parity; immutable-image onboarding with zero Dockerfile builds; real PTY inference; all three exact read-tool proofs passed on their first attempts; native settings and JSONL sessions survived rebuild; sandbox and gateway restart recovery, personal profiles, policy denial, and credential/socket isolation passed. Archive SHA-256 `ff12d31bf47361b31f1bb582eb8e8de87e9409ed3e4bf7443f4d7fb4aa118ed0` matches GitHub metadata. - Cleanup: sandbox destroy and absence checks passed; all four registered cleanup actions passed with no failures (host sandbox, OpenShell sandbox, gateway, Docker build guard). Evidence manifest/upload and Docker auth cleanup passed. - The diff contains no secrets, API keys, or credentials. --- Signed-off-by: San Dang <sdang@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated qualification records for Linux x86-64 and ARM64 builds with revised image references, source revisions, and cohort identifiers. * Refreshed the corresponding verification digests. Product functionality and qualification lookup behavior are unchanged. These updates affect build qualification metadata only; no end-user features or interface changes are included in this release. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: San Dang <sdang@nvidia.com>
## Outcome Custom-Dockerfile OpenClaw onboarding waits for native startup before configuring and restarting the gateway. Rebuild verifies the selected compatible route after restoring configuration, and reports backup/retry details if that proof fails. ## Reason The [baseline job](https://github.com/NVIDIA/NemoClaw/actions/runs/37556111817/job/112596124645) failed initial restart with `ECONNREFUSED`. The [first repaired runtime run](https://github.com/NVIDIA/NemoClaw/actions/runs/37571422820/job/112631546224) confirmed the startup repair and exposed a second ordering error: rebuild verified the baked route before restoring the saved selection. ## Changes - Reuse existing startup/pairing settlement for custom-image native initialization. - Move the compatible-endpoint OpenClaw rebuild proof after restore, startup, and pairing. Retain other providers’ earlier checks and the captured runtime. - Reuse the existing verifier, onboarding wiring, and rebuild failure boundary. Cover failure propagation, backup-aware recovery, and incomplete restoration with focused regressions. - Make the shared baseline HTTP fixture return the required streamed `PONG`, test its authentication, and correct the startup failure diagnostic. The startup hunk and positive regression wiring are adapted from [PR #12382](#12382), attributed to Prekshi Vyas. Open-PR rechecks found no focused duplicate. Dependencies, product scope, live assertions, and deadlines are unchanged. ## Verification Final tested commit: `f74fdbda67280ca7109af048145911599ad6c55d`. - **[Trusted-main E2E run passed](https://github.com/NVIDIA/NemoClaw/actions/runs/37586173737)**; [Docker/mock target job](https://github.com/NVIDIA/NemoClaw/actions/runs/37586173737/job/112677857910) passed all 12 phases. Selectors: `openclaw-inference-switch`, `docker`, `mock`. - Selected route/config/model replaced the baked selection and survived restart and rebuild. Provider switching, expected restart behavior, registry/session checks, `inference.local`, and real gateway `PONG` after onboarding, restart, rebuild, and switching passed. - [Runtime evidence artifact](https://github.com/NVIDIA/NemoClaw/actions/runs/37586173737/artifacts/11467655464): identity manifest plus 101 product evidence files; target result `passed`; all six registered cleanup actions passed with no failures. Temporary Docker authentication was removed successfully. - 506-row assertion ledger includes prerequisites, lifecycle/inference checks, historical unreached assertions, and cleanup. Conditional PID comparison was not exercised because the probe returned no PID (`gatewayPidStable=null`). Hosted LLMs and unselected variants are outside this Docker/mock qualification. - Focused checks: 521 passing tests; negative regressions fail before their repairs. CLI types, source architecture, canonical validator identity, and normal commit/pre-push checks passed. [CI](https://github.com/NVIDIA/NemoClaw/actions/runs/37583022528) and [candidate image qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/37583022513) passed. ## Review notes Author review covers changed onboarding/inference consumers. [All nine Advisor specialists completed with no findings](#12720 (comment)) on this exact commit. Every published commit is GitHub Verified; no secrets or credentials are included. The branch consumes main’s required semantic-phase catalogue. [CodeRabbit completed successfully](#12720 (review)) with two minor diagnostic suggestions (caught transport-error detail and pairing-failure wording), retained as review follow-ups to preserve this passing candidate. No human approval is claimed. Do not merge. --- Signed-off-by: San Dang <sdang@nvidia.com> --------- Signed-off-by: San Dang <sdang@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
PR Review Advisor finished for commit Request review only when Require no Advisor blockers is green. |
Outcome
Updates managed OpenClaw and its official channel/search plugins from 2026.9.2 to 2026.9.5 while preserving NemoClaw's proxy, device authorization, private-state, and tool compatibility behavior.
Reason
OpenClaw 2026.9.5 changes distributed modules to
.mjs, embeds separate worker implementations, changes native patch targets, and changes the package graphs used by offline plugin installation. Version-pin changes alone do not preserve those integrations.Changes
Rebuild runtime and messaging locks with current security overrides and verified archive identities. Preserve the prerequisite trust policy from chore(deps): trust OpenClaw 2026.9.5 manifests #12380; remove obsolete unselected archive entries.
Adapt exact patch targets for
.mjs, the npm 12 parser facade, trimmed device request IDs, private state modes, nested tool input, and MCP npx arguments.Patch the separately bundled worker with drift checks and descriptor-bound writes. Require the worker to exist; cover symlink and replacement-path rejection, idempotence, and actual worker behavior.
Isolate WeChat and official-channel disposable npm caches. Retain resolved lock graphs while seeding metadata for fresh offline installs and supplying the pinned host-override archives.
Update the remote-dashboard guard's exact reviewed messaging-install instruction digest, retaining rejection of appended configuration rewrites. Supply the required worker in synthetic Dockerfile patch fixtures while preserving their package metadata.
Admit reviewed pairing database schemas 15 and 17 while preserving descriptor, identity, credential, and scope checks. Read native token rotation and rollback through the shipped adapter in the real-distribution proof. Explicitly enable the existing NemoClaw prompt-context hook under the new upstream permission policy.
Load the native post-upgrade schema repair and migration-lease checks from both
.jsand.mjsmodules. Find canonical migration SQL in its reviewed state-module family while retaining ambiguity rejection. Exercise both fixture layouts and the actual pinned package after native credential creation.Retire only the global gateway-owner lease from the private SQLite archive copy. This lets a replacement container start without inheriting the retired container’s unexpired lease; the live database and other leases remain unchanged. Fail closed on an unrecognized schema.
Keep the native CLI launcher inside the reviewed OpenClaw package so 2026.9.5 self-update preview recognizes its ownership. Preserve the wrapper’s arguments and npm-prefix behavior.
Preserve main’s Tavily union validator and check the installed 2026.9.5 plugin. Keep the historical Slack remediation test independent of the new production version pins.
Create synthetic worker fixtures exclusively and update their package manifests through one file descriptor, resolving the two CodeQL race findings.
Split archive download stages within image-layer limits, bound the verified larger OpenClaw archive, and update image metadata and current user guidance.
Start the pairing watcher only after the native gateway startup probe succeeds. This prevents its CLI preflight from competing with gateway schema migration for the shared state lock. Keep the captured process identity, a bounded wait, and the existing approval policy.
Repair 9.5 startup and lifecycle handling: remove only empty, owned legacy state files; wait for confirmed gateway readiness, including custom-image onboarding; retain descriptor and file-identity protections.
Support the reviewed 9.5 QR renderer and Slack
.mjsmodules. Keep denied-sender behavior and private feedback intact.Make lifecycle E2E establish the required native admin approval, retain the sandbox namespace, assert plugin-install success, and fail immediately when restore prerequisites are missing. Preserve all existing assertions.
Integrate main's selected-channel offline-cache repair and update the exact Dockerfile instruction digest accepted by the dashboard guard.
Reserve native gateway startup time before the host declares canonical pairing absent. Both ordinary and Portable settlement allow the existing 330-second startup bound plus the existing 60-second device-list window; canonical device identity and scopes still determine success.
Restore the previously approved budget paragraph lost during the JSON conflict resolution. Exception entries, hashes and enforcement remain unchanged.
Preserve native startup failures in the existing managed gateway log and private watcher status. Ordinary and Portable onboarding now distinguish a gateway timeout or exit from a pairing failure and point to the durable diagnostic and recovery action. Existing startup bounds, device identity and approval scope remain unchanged.
Verification
52a0fb1b8e25c3317f5ae62819b4f53420e7d908, including merged SDK prerequisite fix(e2e): install the locked SDK from reviewed archive bundles #12765 and canonical validation updates from fix(test): preserve coverage across native and Vitest loaders #12713.nemoclaw <sandbox> gateway restart.b73ebd8bb5e15cfcf080a21beaca0dce50cbca903988b20be74d49c9498baeb7. Its manifest, lock, raw response and exception-policy hashes were verified. The receipt expires at 2026-10-08T13:49:29.542Z.Review notes
The previous Advisor P1 is resolved. Both OpenClaw onboarding paths now identify the supported gateway restart command after native startup fails, retain the persistent-log path, and instruct the operator to resume onboarding after a successful restart. The current nine specialist reports confirm no blocking findings.
The independent growth check still requires the exact approved budget transition in #12718 to be adopted by trusted main. Candidate policy cannot waive that check. #12718's current CI failed during transitive npm resolution and still needs fresh Advisor clearance. Trusted main also needs the trust policy from #12380 for full 2026.9.5 qualification. The shared E2E controller history lookup was repaired by merged #12790; #12789 was closed as superseded.
Self-review covered the public restart command, both settlement callers, the four failing regression cases followed by 89 passing tests, unchanged Pi receipt inputs, and preservation of the approved budget. This PR remains a draft pending the remaining checks and full E2E evidence. CodeRabbit is deferred at the user's direction; no merge is authorized.
Signed-off-by: Prekshi Vyas prekshiv@nvidia.com