Skip to content

ci(e2e): adopt OpenClaw lifecycle budget exception - #12718

Open
prekshivyas wants to merge 6 commits into
mainfrom
fix/openclaw-12382-e2e-budget-prerequisite
Open

prekshivyas wants to merge 6 commits into
mainfrom
fix/openclaw-12382-e2e-budget-prerequisite

Conversation

@prekshivyas

@prekshivyas prekshivyas commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Outcome

Records the maintainer-approved trusted-base exception needed for PR #12382's OpenClaw lifecycle E2E repair. After maintainer adoption on main, the independent growth check can accept only that PR's recorded budget transition.

Reason

The repaired survival and rebuild tests must obtain native admin approval before privileged fixture mutations. Survival must also check that native plugin installation succeeded. These changes retain the existing lifecycle assertions and add one unique assertion point and one generated probe condition.

The independent check reads its exception policy from the PR base. An entry only in #12382 cannot satisfy that check. This prerequisite makes the proposed exception reviewable independently of the runtime upgrade.

Changes

Verification

  • Ran the unchanged canonical e2eAssertionBudgetGrowthViolations consumer against the real base and candidate budget bytes. The proposed trusted-base policy accepted the specified transition.
  • The same consumer rejected a different PR number, changed base bytes, changed candidate bytes, and an exception present only in candidate policy.
  • Normal signed-commit and publication hooks passed; GitHub verifies the published signature.
  • The diff contains one policy file and no secrets, API keys, or credentials. It changes no runtime code, live scenario, matrix lane, or assertion budget.

Review notes

Prekshi Vyas (@prekshivyas) explicitly approved refreshing this exact budget transition in the task session on October 7, 2026. GitHub's repository permission API confirms the maintain role. The approval is recorded in verified signed commit 435cf418. This records the existing authorization; it is not a formal independent GitHub approval review.

PR #12718 is the separate trusted-base prerequisite for #12382. This PR changes no assertion budget. Its exception must land on main before the independent check for #12382 can use it.

Advisor run 37725477461 completed all nine specialists. The policy comment now states only the digest-bound transition, the trusted-base requirement, and removal after #12382 merges. Approval evidence remains in this review record. The verification finding described a candidate-only exception in #12382; this separate prerequisite implements its recommended landing order. Neither independent enforcement nor any budget digest changed.

Candidate e30328746ef0c3ee9f26cacc2e2b52ae529af5b3 includes the merged test-loader dependency from #12713 so publication uses the canonical validation surface. All 58 existing growth-parser tests passed, including wrong-PR, changed-digest and candidate-only-policy rejection. CI run 37726737536 passed. Advisor run 37728270809 completed all nine specialists with no findings. All findings, summaries, and E2E recommendations were read; no additional live E2E applies to this policy-only change.

Adoption on main remains required before #12382 can satisfy the independent growth check. Independent review and merge remain outstanding.


Signed-off-by: Prekshi Vyas prekshiv@nvidia.com

Summary by CodeRabbit

  • Chores
    • Updated internal validation records for an approved assertion-budget transition and its prerequisite.
    • No user-facing behavior changes.

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: e408773c-65a7-4f1c-bbc6-65eafedf6cd9
📥 Commits

Reviewing files that changed from the base of the PR and between b95c0be and e303287.

📒 Files selected for processing (1)
  • ci/e2e-assertion-growth-exceptions.json

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The assertion-growth policy now documents PR #12718 as a prerequisite for PR #12382’s budget transition. It adds an exception for PR #12382 that matches the specified base and head budget digests.

Changes

Assertion-growth policy

Layer / File(s) Summary
Document prerequisite and add exception
ci/e2e-assertion-growth-exceptions.json
The policy comment documents the prerequisite, digest matching, and removal after PR #12382 merges. A new exception record lists PR #12382 and its base and head budget SHA-256 digests.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Suggested reviewers: ericksoa

Merge Risk: ⚪ Minimal · up to e3032

This adds a narrowly scoped CI exception, with no concrete merge-blocking risk established. Whether it enables PR #12382’s later transition remains unconfirmed because its candidate budget bytes were unavailable.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: adding an OpenClaw lifecycle budget exception in the E2E CI policy.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit e303287 in the fix/openclaw-12382-e... branch is 97%. The line coverage in commit 63002cd in the main branch is 96%.

Show a line coverage summary of the most impacted files.
File main 63002cd fix/openclaw-12382-e... e303287 +/-
nemoclaw/src/onboard/config.ts 98% 96% -2%
nemoclaw/src/index.ts 94% 93% -1%
nemoclaw/src/bl...print/runner.ts 95% 95% 0%
nemoclaw/src/bl...ime-identity.ts 97% 97% 0%
nemoclaw/src/bl...t-management.ts 100% 100% 0%
nemoclaw/src/co.../config-show.ts 100% 100% 0%
nemoclaw/src/commands/slash.ts 100% 100% 0%
nemoclaw/src/on...native-route.ts 0% 100% +100%

TypeScript / code-coverage/cli

The overall line coverage in commit e303287 in the fix/openclaw-12382-e... branch is 86%. The line coverage in commit 63002cd in the main branch is 84%.

Show a line coverage summary of the most impacted files.
File main 63002cd fix/openclaw-12382-e... e303287 +/-
src/lib/onboard.ts 62% 46% -16%
src/lib/onboard...rchestration.ts 41% 32% -9%
src/lib/state/sandbox.ts 92% 84% -8%
src/lib/actions...ess-recovery.ts 65% 78% +13%
src/lib/inferen...file/cleanup.ts 73% 88% +15%
src/lib/state/l...diness-lease.ts 66% 82% +16%
src/lib/inferen...ollama/proxy.ts 41% 61% +20%
src/lib/onboard.../application.ts 55% 84% +29%
src/lib/inferen...nvidia/index.ts 0% 84% +84%
src/lib/onboard...ternal-image.ts 0% 91% +91%

Updated October 08, 2026 04:35 UTC

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Consume the merged test-loader dependency for canonical publication validation.
Preserve every exception and budget digest. Limit the added comment to the
PR 12382 transition and trusted-base prerequisite.

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor finished for commit e303287. Include the Advisor findings in the complete PR feedback collection. Verify and group valid findings before repair.

Request review only when Require no Advisor blockers is green.

All previous runs

@prekshivyas
prekshivyas marked this pull request as ready for review October 8, 2026 04:43

@senthilr-nv senthilr-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review of commit e30328746ef0c3ee9f26cacc2e2b52ae529af5b3

Product scope: Accepted CI-policy prerequisite for PR #12382. The signed maintainer record and the current maintain role establish the decision. This PR adds no supported runtime surface.

Review verdict: APPROVE. I found no blocking correctness, security, architecture, documentation, or data-safety finding. The new record binds PR #12382 to one exact base budget and one exact candidate budget. I recomputed both SHA-256 values from the Git objects. All previous exception records remain present. The independent guardrail reads trusted-base policy and requires the event PR number and both budget digests, so candidate policy cannot approve its own transition. PR #12718 must land before PR #12382 uses this exception. The comment states that order and the removal condition.

Security review: PASS in all nine categories:

  • Secrets and credentials: no credential path or value changes.
  • Input validation and data sanitization: the existing parser requires a positive PR number and 64-character lowercase SHA-256 values.
  • Authentication and authorization: independent enforcement uses the trusted-base policy and event PR number.
  • Dependencies and third-party libraries: no dependency changes.
  • Error handling and logging: malformed policy throws; unmatched growth remains a violation.
  • Cryptography and data protection: SHA-256 binds exact budget bytes; no key or protected-data flow changes.
  • Configuration and security headers: only one bounded CI-policy record changes; runtime controls remain unchanged.
  • Security testing: parser tests cover wrong PR, changed digests, candidate-only policy, and malformed policy.
  • System security: the pull_request_target job runs trusted code and treats PR commits as inert Git objects.

Validation: 65 focused growth-guardrail tests passed with NEMOCLAW_GROWTH_BASE_REF set to the PR base commit b95c0be84e061ba781fedca55e3c1e47af8dcfe1. CodeRabbit and all nine Advisor reports for this commit have no actionable finding. The cross-issue scan found no candidate issue. All six PR commits are GitHub Verified and carry DCO trailers. Feedback collection reached terminal pagination: 4 issue comments, 0 submitted reviews, 0 inline comments, and 0 threads.

Required CI: The live ruleset's checks, commit-lint, dco-check, and check-hash contexts passed on this commit. changes has a permitted skipped result after a successful run on the same commit. Before this review, GitHub reported MERGEABLE and BLOCKED pending review; auto-merge was off.

Files reviewed: ci/e2e-assertion-growth-exceptions.json, .github/workflows/codebase-growth-guardrails.yaml, test/helpers/growth-guardrail-checks.ts, test/helpers/growth-guardrail-diff.ts, test/automation/pull-requests/growth-guardrail-parsers.test.ts, test/automation/pull-requests/growth-guardrails.test.ts, and test/README.md.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants