Repository navigation
fix(pi): refresh qualification receipts from matching source - #12719
Conversation
Signed-off-by: San Dang <sdang@nvidia.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review. 📝 WalkthroughWalkthroughThe AMD64 and ARM64 Pi qualification records now use updated image digests, source revision, and cohort values. The repository-controlled Pi qualification receipt digest list also contains two updated values. ChangesPi qualification records
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The Pi receipt records match their approved hashes, with no demonstrated qualification failure. Their image digests could not be compared with the publication outputs, so that provenance remains unconfirmed, but there is no evidence of a mismatch. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall line coverage in commit 14e1067 in the Show a line coverage summary of the most impacted files.
TypeScript / code-coverage/cliThe overall line coverage in commit 14e1067 in the Show a line coverage summary of the most impacted files.
Updated |
|
PR Review Advisor finished for commit Request review only when Require no Advisor blockers is green. |
|
Review of This is a same-repository NVIDIA branch from CodeRabbit’s publication-provenance limitation is resolved by direct artifact inspection. Both receipts match the downloaded publication artifacts byte-for-byte, their archive hashes match GitHub metadata, and their receipt hashes match the updated authority. All 26 selected Pi image inputs match the publication source. The host-side authority update does not require regenerating the image’s reviewed startup bundle. The code CI run passed for this SHA. Later skipped CI jobs resulted from metadata-only edits, confirmed by reading the complete aggregate-job log. Publication-only skips are expected on PR events; neither condition needs a rerun. All nine Advisor reviews produced findings artifacts for this SHA without blockers. The Pi qualification artifact records real tool calls, rebuild, recovery, isolation, and cleanup for this commit on Linux AMD64/Docker with OpenShell 0.0.116 and NVIDIA inference. It does not establish ARM64 live qualification or full-release qualification. I did not rerun tests locally. |
Outcome
Pi qualification can use immutable images whose source matches the checked-out candidate. The receipt/source check previously failed before onboarding because the recorded image source lacked the current reviewed npm audit input.
Reason
Main E2E run 37556111817, attempt 2 tested
2306bc5f49c7a2f2697e9dfc781b5f4d21dc3580against receipts from545faaf4d3850e8cac9b84d3871e1f4330c26d03. Among the selected Pi image inputs,ci/reviewed-npm-audit.jsondiffers between those sources.Changes
Refresh both architecture receipts from the successful trusted main publication run 37552706149, source
2306bc5f49c7a2f2697e9dfc781b5f4d21dc3580, releasev0.1.0, cohortghrun-37552706149-1. Replace the two approved receipt hashes with the SHA-256 hashes of those exact artifact bytes.sha256:4388a19731121b2d715b7601ff9603eff73a108759d8c46c9b60d5f78e62c3b911453458684sha256:b7d0d5e0af771eff3e58fa169ac61ac63512e6177b9cfd78520005001df636e811454073932The three-file diff preserves Pi candidate status, dependency versions, Linux AMD64/Docker qualification scope, NVIDIA hosted inference, image-input selection, and every qualification assertion. No receipt from #12382 is reused: its dependency-upgrade source and cohort differ. Open PRs were checked for a focused duplicate; #12396 adds supported-agent scope and #12382 changes dependencies.
Verification
Candidate:
14e10676ff003648ed03303338c487325d6b9e18.vitest run --project cli --project integration --project e2e-supportwith the five selected files).node --import tsx scripts/checks/pi-qualification-receipt-refresh.mts: passed on the committed candidate.contract.jsonbytes. AMD64 archived6a029ac0328f64eeeb94e8cfcc96daa99799d47924c0facd18ced9dfb39d0e8; ARM64 archivef9d863f1a449bf6b2a88dd79d19ebab6ea5cd18f56fa6d08c34d8238fcca060c.jobs=pi-agent-qualification,gateway_runtimes=docker,inference_mode=public-nvidia): passed: workflow 37571476855, Pi target job, and Relevant E2E gate. The first dispatch stopped before planning because the exact PR image workflow was still running. Its full prerequisite and downstream logs were inspected; no Pi resources were created. The current run followed verified prerequisite success, with the candidate unchanged.ff12d31bf47361b31f1bb582eb8e8de87e9409ed3e4bf7443f4d7fb4aa118ed0matches GitHub metadata.Signed-off-by: San Dang sdang@nvidia.com
Summary by CodeRabbit