Repository navigation
fix(e2e): use declared external gateway state in Brev lifecycle - #12535
Conversation
The exact main Brev run reached the native-config restart phase but the E2E runner omitted the gateway state override from each isolated child process. The SDK selected an unrelated default under /home/ubuntu and rejected it before sandbox stop or start. Carry the validated external declaration's state root into every test command. Preserve the ownership check and report only a bounded filesystem errno when ancestor inspection fails. Focused E2E fixture and diagnostic tests pass; the missing state override and absent errno were observed failing before these changes. Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
The Launchable gateway has no NemoClaw-managed ownership marker. Passing its declared state directory to the CLI otherwise changes the E2E failure from a missing default root to a missing managed marker. Resolve the selected external declaration in the SDK, bind its HTTPS endpoint and state root to the requested gateway, and accept an unmarked root only under that validated external authority. Keep owner-private directory and mTLS checks; continue to reject an arbitrary unmarked managed override. SDK tests cover declaration-only and explicit state selection, private-root requirements, mismatched port and path, and the original managed denial. Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (7)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall line coverage in commit bad07ee in the Show a line coverage summary of the most impacted files.
Updated |
The OpenShell SDK now loads the gateway-management module to validate an externally supervised gateway. The isolated compiled-package fixture omitted that runtime module, so its two package-contract tests failed with MODULE_NOT_FOUND even though the full CLI package contains it. Include the compiled module in that fixture's package boundary. Both compiled OpenShell SDK package-contract tests pass locally after the change; the exact-head CI failure was observed before it. Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
The Brev lifecycle fix could not reach its live test because inherited image dependency and audit checks failed. Merge main after PR #12507 landed so the candidate consumes the repaired image prerequisites without broadening the gateway-state change. Validated gateway fixture (21), SDK (10), diagnostic (2), and compiled package (2) tests. CLI and plugin builds passed. CLI typecheck passed with the documented 8 GB Node heap setting. The selected live E2E still needs exact-candidate execution. Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
Outcome
Brev Launchable lifecycle commands use the gateway state directory declared by the preinstalled image. The OpenShell SDK accepts that externally supervised gateway without a NemoClaw-managed ownership marker, while retaining private-directory and local mTLS checks.
Reason
The main Brev E2E run 36890457594, attempt 2 built and booted the image, passed inference and credential checks, then failed at
nemoclaw e2e-staging stop/start: the SDK selected the missing default state path under/home/ubuntu/.local/state/nemoclawinstead of/var/lib/brev/openshell-gateway. Passing the correct path also requires recognizing the external supervisor's ownership contract.Changes
ccf68daed3aa8dc1c6bf074b9ee3d32cad684295to consume the image prerequisite repairs merged in fix(ci): upgrade OpenClaw and repair audit and runtime qualification #12507. The candidate delta remains seven files; it does not change image or audit policy.Verification
On candidate
bad07eee6c20d8b452589fc2c6d2d2a77201c723:npm run build:cliandnpm --prefix nemoclaw run build— passed.NODE_OPTIONS=--max-old-space-size=8192 npm run typecheck:cli— passed. The first attempt exhausted Node's default 4 GB heap.Selected exact-candidate E2E:
onboard-repair,onboard-resume, and a separatestaging-brev-launchablerun, from deterministic risk plan v26. Live results remain pending; historical green checks do not establish a pass for this head.Review notes
Sensitive paths:
src/lib/onboard/gateway/state-dir.tsand its ownership test. The local Docker Advisor could not review the previous final candidate because its trusted checkout ran out of disk (TAR_ENTRY_ERROR ENOSPC). The existing Lima VM still has only about 1.4 GB free; a subsequent review also failed during image unpacking. No Advisor clearance is claimed for this head.Under the authorized alternative review path, the full seven-file diff was reviewed against canonical main for correctness, ownership and credential boundaries, affected callers, regression coverage, and test selection. A 383-row assertion ledger records the Brev setup, stop/start, native model restoration, both interactive launches, native plugin operations, teardown, evidence, and downstream workflow gates. The pinned OpenClaw 2026.9.2 package checksum and relevant output producers were inspected. No additional source-supported repair was found; live process behavior and provider availability remain runtime dependencies.
The prior main Brev run's owned workspace was verified
ABSENT. The old PR-head reviews contain no actionable threads; hosted review and exact-head CI/E2E must still settle before ready-for-review.Both npm audit checks now pass. CLI shard 9 failed in main's unchanged Ollama timeout test:
/proc/<pid>/statreturnedESRCHafter process reaping, while the assertion accepts onlyENOENT. A real Linux Node 24.18.1 open/reap/read probe confirmed that result; the original assertion rejects it and the minimal repair accepts it while retaining the absent-or-zombie check. A separate signed test-only repair is prepared locally as5165a0a5c4a7e2180d909da4f5b195e1d4233637(29 focused tests passed, two Linux-only tests skipped on macOS). Its dependency PR awaits an available slot under the repository's 10-open-PR limit. Image qualification and selected E2E remain pending.Signed-off-by: Julie Yaunches jyaunches@nvidia.com
Latest exact-candidate E2E and image dependency
Onboarding run 36933114852 passed all three selected jobs on
bad07eee6c. Brev run 36933109713, attempt 1 passed exact image provenance and gateway-state preflight, then failed native stop/start with SDKERR_MODULE_NOT_FOUND. Its owned workspace was deleted and verified absent. Later PTY/plugin assertions remain unexecuted.brevdev/nemoclaw-image#191 fixes the image installer’s missing SDK archive preparation and import verification. It must be reviewed and merged before the next Brev image run. The separate inherited Linux process-test race still needs the prepared dependency PR, currently blocked by the contributor open-PR limit. This PR remains draft; no overall readiness or Advisor clearance is claimed.