Repository navigation
fix(e2e): accept retired OpenClaw config hash - #12408
prekshivyas wants to merge 1 commit into
Conversation
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
This repository limits you to 10 open pull requests. Please close or merge an existing PR before opening another one. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (2)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall line coverage in commit 85a6547 in the TypeScript / code-coverage/cliThe overall line coverage in commit 85a6547 in the Show a line coverage summary of the most impacted files.
Updated |
|
PR Review Advisor finished for commit Request review only when Require no Advisor blockers is green. |
deepujain
left a comment
There was a problem hiding this comment.
Reviewed commit 85a6547c0e. No code defect found. The probe retains heartbeat validation, accepts an absent retired .config-hash, and still fails for stale or dangling legacy entries. All 55 protected-runtime contract tests passed locally, including real shell/filesystem checks. Current CI, managed-image validation, and self-hosted PR qualification passed.
I read all nine Advisor reports. The customer-value, migration, and security findings repeat one objection: requiring the hash to remain mandatory. I do not consider that a blocker for this compatibility step. Accepted issue #11764 explicitly removes whole-config hash authorization, and #12120 needs the trusted probe on main to accept the new representation before qualification. This PR preserves verification when a legacy entry remains and does not change production authorization or credential custody.
Approval is pending CodeRabbit completion. The trusted checker reports that as its only failing gate; the PR is conflict-free and contributor verification passes. The focused local tests are not a new full protected-runtime E2E run.
|
Closing as superseded by #12120, which merged as |
Outcome
Trusted protected managed-image E2E accepts an OpenClaw configuration after removal of
.config-hash. If a legacy hash entry remains, qualification still verifies it and rejects stale or dangling entries.Reason
PR #12120 removes the NemoClaw-owned OpenClaw configuration hash. The trusted workflow from
maincurrently requires that file, so it cannot qualify the candidate commit after the file is removed.Related issues
Part of #11764
Changes
.config-hash.The
managed-image-protected-runtimeE2E job must qualify both existing images that retain the legacy entry and PR #12120, which removes it. Removing hash verification without a compatibility condition would stop validating existing legacy entries. The protected-runtime contract test covers both states.Verification
npx vitest run --project integration test/inference/managed/managed-image-protected-runtime-contract.test.ts— 55 tests passed.npx vitest run --project integration test/automation/pull-requests/growth-guardrails.test.ts— 7 tests passed.npm run checks:repository— 18 checks passed.NODE_OPTIONS=--max-old-space-size=8192 npm run typecheck:cli— passed.git diff --checkand focused Oxfmt verification — passed.Review notes
This PR must merge before a new full E2E run can qualify the final PR #12120 commit through trusted
main.Sensitive-path review verified that only absence of the retired OpenClaw hash is accepted. Present stale or dangling entries still fail, and Hermes, LangChain Deep Agents, and shared protected-runtime checks are unchanged.
no-docs-needed.config-hashwhen absent while validating any legacy entry that remains. It does not change a supported user-visible surface. The final protected-runtime contract passed 55/55, growth guardrails passed 7/7, all 18 repository checks passed, and formatting and diff checks passed.Codex DesktopSigned-off-by: Prekshi Vyas prekshiv@nvidia.com