Skip to content

fix(e2e): accept retired OpenClaw config hash - #12408

Closed
prekshivyas wants to merge 1 commit into
mainfrom
codex/12120-trusted-openclaw-probe
Closed

prekshivyas wants to merge 1 commit into
mainfrom
codex/12120-trusted-openclaw-probe

Conversation

@prekshivyas

Copy link
Copy Markdown
Collaborator

Outcome

Trusted protected managed-image E2E accepts an OpenClaw configuration after removal of .config-hash. If a legacy hash entry remains, qualification still verifies it and rejects stale or dangling entries.

Reason

PR #12120 removes the NemoClaw-owned OpenClaw configuration hash. The trusted workflow from main currently requires that file, so it cannot qualify the candidate commit after the file is removed.

Related issues

Part of #11764

Changes

  • Make the trusted OpenClaw heartbeat probe accept an absent retired .config-hash.
  • Preserve legacy hash verification when the entry exists, including a dangling symbolic link.
  • Add protected-runtime contract cases for absent, matching, stale, and dangling legacy hash entries.

The managed-image-protected-runtime E2E job must qualify both existing images that retain the legacy entry and PR #12120, which removes it. Removing hash verification without a compatibility condition would stop validating existing legacy entries. The protected-runtime contract test covers both states.

Verification

  • npx vitest run --project integration test/inference/managed/managed-image-protected-runtime-contract.test.ts — 55 tests passed.
  • npx vitest run --project integration test/automation/pull-requests/growth-guardrails.test.ts — 7 tests passed.
  • npm run checks:repository — 18 checks passed.
  • NODE_OPTIONS=--max-old-space-size=8192 npm run typecheck:cli — passed.
  • Pre-commit, commit-message, and pre-push hooks — passed.
  • git diff --check and focused Oxfmt verification — passed.
  • The diff contains no secrets, API keys, or credentials.

Review notes

This PR must merge before a new full E2E run can qualify the final PR #12120 commit through trusted main.

Sensitive-path review verified that only absence of the retired OpenClaw hash is accepted. Present stale or dangling entries still fail, and Hermes, LangChain Deep Agents, and shared protected-runtime checks are unchanged.

  • Documentation writer subagent reviewed the completed changes
  • Result: no-docs-needed
  • Evidence: The change only updates trusted protected-E2E qualification to accept the retired OpenClaw .config-hash when absent while validating any legacy entry that remains. It does not change a supported user-visible surface. The final protected-runtime contract passed 55/55, growth guardrails passed 7/7, all 18 repository checks passed, and formatting and diff checks passed.
  • Agent: Codex Desktop

Signed-off-by: Prekshi Vyas prekshiv@nvidia.com

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@prekshivyas prekshivyas self-assigned this Sep 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

This repository limits you to 10 open pull requests. Please close or merge an existing PR before opening another one.

@github-actions github-actions Bot closed this Sep 28, 2026
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: ebbad3da-02f7-4141-aded-cfe6b6711c33

📥 Commits

Reviewing files that changed from the base of the PR and between d612681 and 85a6547.

📒 Files selected for processing (2)
  • scripts/checks/run-managed-image-openshell-e2e.ts
  • test/inference/managed/managed-image-protected-runtime-contract.test.ts
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 85a6547 in the codex/12120-trusted-... branch remains at 96%, unchanged from commit 63002cd in the main branch.

TypeScript / code-coverage/cli

The overall line coverage in commit 85a6547 in the codex/12120-trusted-... branch remains at 84%, unchanged from commit 63002cd in the main branch.

Show a line coverage summary of the most impacted files.
File main 63002cd codex/12120-trusted-... 85a6547 +/-
src/lib/actions...flight-phase.ts 98% 90% -8%
src/lib/sandbox/config.ts 70% 67% -3%
src/lib/state/o...d-checkpoint.ts 87% 84% -3%
src/lib/actions...up-authority.ts 73% 70% -3%
src/lib/onboard...rchestration.ts 41% 40% -1%
src/lib/state/sandbox.ts 92% 92% 0%
src/lib/state/o...oard-session.ts 88% 89% +1%
src/lib/actions...estore-phase.ts 70% 75% +5%
src/lib/agent/s...store-reader.ts 86% 92% +6%
src/lib/onboard...ure-evidence.ts 70% 90% +20%

Updated September 28, 2026 22:07 UTC

@prekshivyas prekshivyas reopened this Sep 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

PR Review Advisor finished for commit 85a6547. Include the Advisor findings in the complete PR feedback collection. Verify and group valid findings before repair.

Request review only when Require no Advisor blockers is green.

All previous runs

@deepujain deepujain left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed commit 85a6547c0e. No code defect found. The probe retains heartbeat validation, accepts an absent retired .config-hash, and still fails for stale or dangling legacy entries. All 55 protected-runtime contract tests passed locally, including real shell/filesystem checks. Current CI, managed-image validation, and self-hosted PR qualification passed.

I read all nine Advisor reports. The customer-value, migration, and security findings repeat one objection: requiring the hash to remain mandatory. I do not consider that a blocker for this compatibility step. Accepted issue #11764 explicitly removes whole-config hash authorization, and #12120 needs the trusted probe on main to accept the new representation before qualification. This PR preserves verification when a legacy entry remains and does not change production authorization or credential custody.

Approval is pending CodeRabbit completion. The trusted checker reports that as its only failing gate; the PR is conflict-free and contributor verification passes. The focused local tests are not a new full protected-runtime E2E run.

@prekshivyas

Copy link
Copy Markdown
Collaborator Author

Closing as superseded by #12120, which merged as e6cff33196e32548c6437bea667bfd31f94adde7 and now places the retired-hash probe on trusted main. The original ordering prerequisite no longer exists. The ordinary whole/default E2E suite is running against that exact merged commit: https://github.com/NVIDIA/NemoClaw/actions/runs/36492952267.

@wscurran wscurran added area: e2e End-to-end tests, nightly failures, or validation infrastructure area: security Security controls, permissions, secrets, or hardening chore Build, CI, dependency, or tooling maintenance integration: openclaw OpenClaw integration behavior labels Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: e2e End-to-end tests, nightly failures, or validation infrastructure area: security Security controls, permissions, secrets, or hardening chore Build, CI, dependency, or tooling maintenance integration: openclaw OpenClaw integration behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants