Skip to content

fix(pi): refresh qualification receipts from matching source - #12719

Merged
sandl99 merged 1 commit into
mainfrom
fix/pi-source-parity-qualification
Oct 7, 2026
Merged

sandl99 merged 1 commit into
mainfrom
fix/pi-source-parity-qualification

Conversation

@sandl99

@sandl99 sandl99 commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Outcome

Pi qualification can use immutable images whose source matches the checked-out candidate. The receipt/source check previously failed before onboarding because the recorded image source lacked the current reviewed npm audit input.

Reason

Main E2E run 37556111817, attempt 2 tested 2306bc5f49c7a2f2697e9dfc781b5f4d21dc3580 against receipts from 545faaf4d3850e8cac9b84d3871e1f4330c26d03. Among the selected Pi image inputs, ci/reviewed-npm-audit.json differs between those sources.

Changes

Refresh both architecture receipts from the successful trusted main publication run 37552706149, source 2306bc5f49c7a2f2697e9dfc781b5f4d21dc3580, release v0.1.0, cohort ghrun-37552706149-1. Replace the two approved receipt hashes with the SHA-256 hashes of those exact artifact bytes.

Platform Published digest Publication job Contract artifact
Linux AMD64 sha256:4388a19731121b2d715b7601ff9603eff73a108759d8c46c9b60d5f78e62c3b9 Publish and validate Pi candidate 11453458684
Linux ARM64 sha256:b7d0d5e0af771eff3e58fa169ac61ac63512e6177b9cfd78520005001df636e8 Publish and validate Pi candidate 11454073932

The three-file diff preserves Pi candidate status, dependency versions, Linux AMD64/Docker qualification scope, NVIDIA hosted inference, image-input selection, and every qualification assertion. No receipt from #12382 is reused: its dependency-upgrade source and cohort differ. Open PRs were checked for a focused duplicate; #12396 adds supported-agent scope and #12382 changes dependencies.

Verification

Candidate: 14e10676ff003648ed03303338c487325d6b9e18.

  • Existing candidate authority, qualified candidate, receipt refresh, runtime artifact, and qualification event tests: 5 files, 78 tests passed (vitest run --project cli --project integration --project e2e-support with the five selected files).
  • node --import tsx scripts/checks/pi-qualification-receipt-refresh.mts: passed on the committed candidate.
  • Exact publication artifacts: archive SHA-256 values match GitHub metadata; both committed receipts equal their downloaded contract.json bytes. AMD64 archive d6a029ac0328f64eeeb94e8cfcc96daa99799d47924c0facd18ced9dfb39d0e8; ARM64 archive f9d863f1a449bf6b2a88dd79d19ebab6ea5cd18f56fa6d08c34d8238fcca060c.
  • Source parity: all 26 selected image paths match the publication source; the old source returns exit 1 and the refreshed source returns exit 0.
  • Assertion audit: 203 predicate rows traced through receipt validation, onboarding, all three read-tool scenarios, real PTY inference, native state, rebuild, restart recovery, security, evidence, and cleanup. Full runtime evidence passed on the exact final candidate; no assertions changed.
  • Normal pre-commit and commit-message hooks passed, including repository checks, secret scanning, and growth guardrails. Normal pre-push publication validation and all three compiler checks passed.
  • PR CI: passed. Advisor: all nine exact-head specialist reviews clear; blocker gate passed.
  • Exact PR image prerequisite: passed, including both native Pi architecture validations and Docker/rootless Podman activation. Its three shipped-agent contract archives were verified against artifact metadata and the exact PR head/cohort.
  • Focused trusted-main exact-head GitHub E2E (jobs=pi-agent-qualification, gateway_runtimes=docker, inference_mode=public-nvidia): passed: workflow 37571476855, Pi target job, and Relevant E2E gate. The first dispatch stopped before planning because the exact PR image workflow was still running. Its full prerequisite and downstream logs were inspected; no Pi resources were created. The current run followed verified prerequisite success, with the candidate unchanged.
  • Qualification evidence artifact 11460609789: exact CLI/image/source/cohort/receipt identity; receipt/source parity; immutable-image onboarding with zero Dockerfile builds; real PTY inference; all three exact read-tool proofs passed on their first attempts; native settings and JSONL sessions survived rebuild; sandbox and gateway restart recovery, personal profiles, policy denial, and credential/socket isolation passed. Archive SHA-256 ff12d31bf47361b31f1bb582eb8e8de87e9409ed3e4bf7443f4d7fb4aa118ed0 matches GitHub metadata.
  • Cleanup: sandbox destroy and absence checks passed; all four registered cleanup actions passed with no failures (host sandbox, OpenShell sandbox, gateway, Docker build guard). Evidence manifest/upload and Docker auth cleanup passed.
  • The diff contains no secrets, API keys, or credentials.

Signed-off-by: San Dang sdang@nvidia.com

Summary by CodeRabbit

  • Chores
    • Updated qualification records for Linux x86-64 and ARM64 builds with revised image references, source revisions, and cohort identifiers.
    • Refreshed the corresponding verification digests. Product functionality and qualification lookup behavior are unchanged. These updates affect build qualification metadata only; no end-user features or interface changes are included in this release.

Signed-off-by: San Dang <sdang@nvidia.com>
@sandl99 sandl99 self-assigned this Oct 7, 2026
@copy-pr-bot

copy-pr-bot Bot commented Oct 7, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 895c3b97-a9ac-4236-be1e-6b98397576ec
📥 Commits

Reviewing files that changed from the base of the PR and between 2306bc5 and 14e1067.

📒 Files selected for processing (3)
  • ci/pi-agent-qualification-v1-linux-amd64.json
  • ci/pi-agent-qualification-v1-linux-arm64.json
  • src/lib/agent/candidate-authority.ts

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The AMD64 and ARM64 Pi qualification records now use updated image digests, source revision, and cohort values. The repository-controlled Pi qualification receipt digest list also contains two updated values.

Changes

Pi qualification records

Layer / File(s) Summary
Qualification records and receipt digests
ci/pi-agent-qualification-v1-linux-amd64.json, ci/pi-agent-qualification-v1-linux-arm64.json, src/lib/agent/candidate-authority.ts
The AMD64 and ARM64 records now use updated image digests, source revision, and cohort values. The Pi receipt digest list now contains two new SHA-256 values.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Suggested reviewers: ericksoa

Merge Risk: ⚪ Minimal · up to 14e10

The Pi receipt records match their approved hashes, with no demonstrated qualification failure. Their image digests could not be compared with the publication outputs, so that provenance remains unconfirmed, but there is no evidence of a mismatch.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: refreshing Pi qualification receipts to match the trusted publication source.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 14e1067 in the fix/pi-source-parity... branch is 97%. The line coverage in commit 63002cd in the main branch is 96%.

Show a line coverage summary of the most impacted files.
File main 63002cd fix/pi-source-parity... 14e1067 +/-
nemoclaw/src/onboard/config.ts 98% 96% -2%
nemoclaw/src/index.ts 94% 93% -1%
nemoclaw/src/bl...t-management.ts 100% 100% 0%
nemoclaw/src/co.../config-show.ts 100% 100% 0%
nemoclaw/src/commands/slash.ts 100% 100% 0%
nemoclaw/src/on...native-route.ts 0% 100% +100%

TypeScript / code-coverage/cli

The overall line coverage in commit 14e1067 in the fix/pi-source-parity... branch is 85%. The line coverage in commit 63002cd in the main branch is 84%.

Show a line coverage summary of the most impacted files.
File main 63002cd fix/pi-source-parity... 14e1067 +/-
src/lib/state/s...tory-restore.ts 86% 0% -86%
src/lib/actions.../status-text.ts 84% 46% -38%
src/lib/state/sandbox.ts 92% 83% -9%
src/lib/onboard...al-inference.ts 84% 90% +6%
src/lib/policy/index.ts 71% 79% +8%
src/lib/state/p...l-retirement.ts 79% 92% +13%
src/lib/onboard.../application.ts 55% 72% +17%
src/lib/adapter...gnostics-cli.ts 0% 87% +87%
src/lib/onboard...ternal-image.ts 0% 94% +94%
src/lib/securit...ig-structure.ts 0% 98% +98%

Updated October 07, 2026 04:08 UTC

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor finished for commit 14e1067. Include the Advisor findings in the complete PR feedback collection. Verify and group valid findings before repair.

Request review only when Require no Advisor blockers is green.

All previous runs

@sandl99
sandl99 marked this pull request as ready for review October 7, 2026 04:37
@hunglp6d

hunglp6d commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Review of 14e10676ff003648ed03303338c487325d6b9e18 against main at feff07d (merge-base 2306bc5): I found no actionable correctness, security, or test-coverage issue in this receipt refresh. The PR SHA was unchanged when I completed the review. I recommend approval; GitHub still requires an authorized reviewer’s approval before merge.

This is a same-repository NVIDIA branch from sandl99, identified by GitHub as a member, with a verified commit signature. Fork workflow restrictions do not apply. The change introduces no new dependency, installer behavior, workflow permission, or secret access.

CodeRabbit’s publication-provenance limitation is resolved by direct artifact inspection. Both receipts match the downloaded publication artifacts byte-for-byte, their archive hashes match GitHub metadata, and their receipt hashes match the updated authority. All 26 selected Pi image inputs match the publication source. The host-side authority update does not require regenerating the image’s reviewed startup bundle.

The code CI run passed for this SHA. Later skipped CI jobs resulted from metadata-only edits, confirmed by reading the complete aggregate-job log. Publication-only skips are expected on PR events; neither condition needs a rerun. All nine Advisor reviews produced findings artifacts for this SHA without blockers.

The Pi qualification artifact records real tool calls, rebuild, recovery, isolation, and cleanup for this commit on Linux AMD64/Docker with OpenShell 0.0.116 and NVIDIA inference. It does not establish ARM64 live qualification or full-release qualification. I did not rerun tests locally.

@sandl99
sandl99 merged commit bced57c into main Oct 7, 2026
150 checks passed
@sandl99
sandl99 deleted the fix/pi-source-parity-qualification branch October 7, 2026 05:19
@github-actions github-actions Bot added the v0.0.132 Release target label Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v0.0.132 Release target

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants