Skip to content

ci(e2e): qualify candidate Deep Agents base in protected startup - #12848

Closed
prekshivyas wants to merge 2 commits into
mainfrom
fix/pr-12376-trusted-v2-controller
Closed

prekshivyas wants to merge 2 commits into
mainfrom
fix/pr-12376-trusted-v2-controller

Conversation

@prekshivyas

Copy link
Copy Markdown
Collaborator

Outcome

The protected full E2E workflow can build the Deep Agents base from the selected candidate revision on both CPU architectures and pass the exact verified base to the GPU job offline. The existing published-base contract remains accepted for earlier revisions.

Reason

The trusted main workflow still requires a published Deep Agents base built from an older DCode revision. That prevents the candidate upgrade in #12376 from reaching its protected full E2E scenarios, even when its own managed-image activation passes. The protected controller must understand the candidate-base contract independently of the candidate checkout.

Related issues

Refs #12376.

Changes

  • Accept contract v2 only when dcodeBaseSource is candidate, while retaining the exact v1 published-base path. The trusted CPU build produces the selected revision's OCI base and a receipt bound to source revision, workflow, run cohort, platform, manifest, config, and layers. The GPU job verifies those bytes before using the same-run offline base; it does not fetch an unreviewed replacement image.
  • Parse manifest and config from the same bytes whose digest was checked. A regression swaps the manifest immediately after verification and proves the altered layer list cannot bypass validation.
  • Carry the existing Launchable opt-out through automatic E2E planning so the selected full suite does not silently add staging Launchable. Contract, build, receipt, workflow-boundary, and planner tests cover the new path and the unchanged legacy path.

Verification

  • Seven focused test files: 569 passed, including the manifest-swap regression.
  • npm run checks:repository: all 18 checks passed.
  • Normal signed commit hooks passed for both commits; the feature worktree is clean.
  • Credential-free isolated Linux npm run check on the exact final commit: passed, including all pre-commit checks, CLI coverage, and plugin tests. The run used the normal per-user launch-readiness authority directory in a private tmpfs, the completed plugin build, the default npm prefix, and bounded prek/Vitest workers to fit the 8 GB Docker VM. No test or gate was skipped.
  • Host macOS npm run check on the same commit: 38,221 tests passed and 90 integration tests failed across 31 unchanged test files, including Linux Bash mapfile and OpenShell Homebrew trust dependencies. None of the failed test files are in this PR's diff; the complete Linux gate above passed.
  • The diff contains no secrets, API keys, or credentials.

Review notes

This draft changes sensitive workflow, script, and E2E enforcement paths. The pre-publication review context is a self-review of NVIDIA/NemoClaw commit 781199f0ca36255b1b12bdf9fa9d2f0258ab6f62 against its starting main ddfbcd20380954f1fd3de0aec05c5fa939948c0d, with the focused tests and isolated gate above. Main later advanced to c518e121d23c616da1b083c44c9eb504fb419ebd; an exact merge-tree preview has no conflict. The E2E planner is necessarily a changed transitive validation helper, so the Linux gate is an explicitly authorized isolated qualification, not a claim that every validator helper is byte-identical to main. Earlier incomplete Linux attempts and the macOS result are recorded in the local validation evidence; the final Linux gate passed, and candidate CI must still pass. Main now includes an Ubuntu mirrorlist repair for the earlier APT-blocked main CI. No independent pre-publication approval has been observed; these paths await review. The full protected E2E outcome remains pending adoption of this trusted controller and a fresh exact-head dispatch for #12376.


Signed-off-by: Prekshi Vyas prekshiv@nvidia.com

Hash and parse the same manifest and config bytes so a path swap cannot bypass layer verification.
Stream layers without buffering and reject size changes during reads.
Add a regression that swaps a verified manifest before parsing.
@copy-pr-bot

copy-pr-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

This repository limits you to 10 open pull requests. Please close or merge an existing PR before opening another one.

@github-actions github-actions Bot closed this Oct 8, 2026
@github-code-quality

github-code-quality Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 781199f in the fix/pr-12376-trusted... branch is 97%. The line coverage in commit 63002cd in the main branch is 96%.

Show a line coverage summary of the most impacted files.
File main 63002cd fix/pr-12376-trusted... 781199f +/-
nemoclaw/src/onboard/config.ts 98% 96% -2%
nemoclaw/src/index.ts 94% 93% -1%
nemoclaw/src/bl...print/runner.ts 95% 95% 0%
nemoclaw/src/bl...ime-identity.ts 97% 97% 0%
nemoclaw/src/bl...t-management.ts 100% 100% 0%
nemoclaw/src/co.../config-show.ts 100% 100% 0%
nemoclaw/src/commands/slash.ts 100% 100% 0%
nemoclaw/src/on...native-route.ts 0% 100% +100%

TypeScript / code-coverage/cli

The overall line coverage in commit 781199f in the fix/pr-12376-trusted... branch is 86%. The line coverage in commit 63002cd in the main branch is 84%.

Show a line coverage summary of the most impacted files.
File main 63002cd fix/pr-12376-trusted... 781199f +/-
src/lib/onboard.ts 62% 46% -16%
src/lib/onboard...rchestration.ts 41% 32% -9%
src/lib/state/sandbox.ts 92% 84% -8%
src/lib/actions...ess-recovery.ts 65% 78% +13%
src/lib/inferen...file/cleanup.ts 73% 88% +15%
src/lib/state/l...diness-lease.ts 66% 82% +16%
src/lib/inferen...ollama/proxy.ts 41% 61% +20%
src/lib/onboard.../application.ts 55% 84% +29%
src/lib/inferen...nvidia/index.ts 0% 84% +84%
src/lib/onboard...ternal-image.ts 0% 91% +91%

Updated October 08, 2026 18:07 UTC

prekshivyas added a commit that referenced this pull request Oct 9, 2026
…2847)

## Outcome

PR E2E uses the upgrade commit's reviewed dependency inputs instead of
forcing main's versions. This change consolidates #12848's Deep Agents
controller fix and extends candidate selection through protected CPU/GPU
image builds and the OpenShell host runtime.

The acceptance target is at most two PRs for upgrades to existing
supported dependencies: normally one upgrade PR, plus one
trust/bootstrap prerequisite when necessary. Ordinary version bumps must
not need a third workflow-fix PR.

## Reason

OpenShell #12603 needs candidate runtime qualification, and Deep Agents
#12376 needs its candidate base in the protected controller. Selecting
candidate artifacts only in ordinary jobs leaves protected consumers on
main's dependencies. Pi also needs to publish source before it can
attach the resulting qualification receipts.

## Changes

- Resolve a reviewed OpenShell release from fixed files at the candidate
commit. Run this resolver only for its selected gateway consumers.
Candidate source remains inert input to pin and operational-template
verification.
- Derive image prerequisites from the existing workflow dependency
graph. Gateway-only and native-producer selections do not wait for
unused image publication. Image consumers and full release qualification
retain their gates.
- Reuse the existing candidate image path for OpenClaw, Hermes, Deep
Agents, Pi, OpenShell and shared npm inputs. Published base reuse now
checks Dockerfiles, parser inputs, ignore rules and copied files for all
three managed agents.
- Build candidate OpenClaw, Hermes and Deep Agents bases on native CPU
runners. Export each as OCI content with its agent, source, workflow,
platform and run identity. Protected GPU consumers verify those bytes
and identities before offline use; they reject published-base
substitution for PR runs.
- Project only reviewed OpenShell modules and release literals into the
trusted GPU controller. Select the reviewed candidate SDK archive,
retain the trusted dependency graph, then build and verify the CLI.
Restore the seven projected source files after qualification. These
steps reuse existing pin, archive and dependency-resolution controls
because arbitrary candidate host code cannot run with protected
credentials.
- Reuse main's Pi `--publication` check for local source publication,
including later repairs in the same PR. The same PR then adds both
published receipts and matching authority. CI remains strict; partial
refreshes and source drift fail.
- Retain verified-byte receipt parsing, staging Launchable opt-in,
failure propagation, resource cleanup and full-release gates. Update the
owning E2E guidance.
- Refresh both Pi qualification receipts from the successful candidate
image publication. Correct the managed-base fixture's platform and
image-label inputs. Validate and read protected files through the same
descriptor, with symlink and hardlink rejection tests. Add fixed,
non-secret approval-selector failure categories without changing its
acceptance rules.

## Verification

Current commit: `da4ce1d219e538cab23cb519aa65e90fda55c8e7`; base:
`6a02aac7f0053978a20eaed73159386e0ad2aff9`.

- [Core CI](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126626)
passed, including all twelve CLI shards, coverage, static checks and the
final gate. [Security
scanning](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126621)
passed.
- [Managed-image publication and
activation](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126620)
passed. Both native Pi producers and all three managed-agent producers
succeeded. Docker and Podman artifacts bind the current commit and image
digests. Each reports 28 controlled-inference turns, zero activation
builds and 13 successful cleanup callbacks.
- [Self-hosted GPU
qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/37865127484)
passed on attempt 2. The initial selector timed out before managed
publication completed; one affected-job rerun after publication
succeeded passed selection and the live test. Verified evidence binds
`da4ce1d`, records full GPU offload, an authenticated real OpenClaw
agent turn, public runtime destruction and provider resources already
absent. All three cleanup callbacks passed.
- [Focused manual
qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/37869966568)
passed from trusted main, including Relevant E2E. All five selected jobs
passed: cloud onboarding, full OpenClaw E2E, Hermes E2E, and
OpenClaw/Hermes security posture. Verified artifacts bind the current PR
commit, workflow and dispatch correlation; each reports one passed test
with no failures, skips or errors. All recorded cleanup callbacks
passed. These tests do not establish candidate OpenShell 0.1.2 coverage.
Jetson, DGX Spark queue and staging Launchable opt-ins were false; full
Release qualification was not selected.
- Focused local validation of the expanded repair passed 13 files / 571
distinct tests. Projection tests cover immutable commits, reviewed
templates, SDK integrity, dependency metadata, tampering, filesystem
redirection, rollback and restoration. Executable SDK fixtures exercise
installation/import without lifecycle scripts or package credentials.
- Image handoff tests cover three agents and both native platforms. They
reject wrong-agent, source, workflow, run, platform and digest evidence.
Dependency-input regressions select candidate artifacts without workflow
edits and reject fallback to main after failed candidate publication.
- OpenShell #12603 package and lock inputs at
`f473315ca9b64cab56305f3bf4a15a877f0904b2` select reviewed SDK `0.1.2`
through the pure projector. This is not live SDK/runtime qualification.
- All four Pi checker/runner conflicts are resolved; those files match
the recorded main commit. The isolated checker/runner suite passed 57
tests. Normal commit hooks, isolated pre-push publication validation and
CLI TypeScript passed. All six PR commits are GitHub Verified.
- Local broad coverage could not finish under the approved macOS
isolation. The current Linux CI coverage result above supplies the
completed broad gate; no local broad-check pass or waiver is claimed.
- The diff contains no secrets, API keys or credentials.

## Review notes

Sensitive paths include `.github/workflows/e2e.yaml`, changed
`scripts/**`, `tools/e2e/**` and
`tools/pr-review-advisor/REVIEW-QUEUE.md`. Source self-review covers
candidate admission, protected execution, prerequisite propagation,
OCI/SDK verification and cleanup.

The [actual Advisor
run](https://github.com/NVIDIA/NemoClaw/actions/runs/37866718854)
reviewed current commit `da4ce1d` against base `6a02aac7`. All nine
specialists completed with no findings. Their artifacts and published
review were read. The deterministic E2E floor remains required; clear
reviews do not waive it.

[CodeRabbit's actual
review](#12847 (comment))
covers the final repair from `2cde38759` to `da4ce1d` and reports no
actionable comments. All three recorded review threads are resolved.
Earlier parity, receipt, fixture, pathname-race and diagnostic findings
were repaired; current core CI and security scanning passed afterward.

All reported PR checks and the focused manual E2E run are green on
`da4ce1d`. GitHub reports no merge conflicts, but human review remains
required. The protected qualification boundary below remains unresolved;
no automated review grants human approval or merge authority.

### Remaining qualification boundary

Current trusted main accepts only the v1 protected activation contract;
this PR introduces the v2 controller needed by candidate builds. Running
that known-rejected protected path before adoption would not qualify it.
Live protected candidate OpenShell/SDK projection therefore still needs
the adopted trusted controller, followed by testing the existing upgrade
PR. No third workflow PR should be needed for that supported path.

The completed Docker/Podman tests do not establish OpenShell 0.1.2
coverage or every dependency combination. Both current native Pi
publications and strict CI passed; Pi source publication and receipt
attachment remain within this PR. New release trust, SDK dependency
graphs, permissions or controller protocols may require the one allowed
trust/bootstrap prerequisite.

This PR does not claim full release qualification, waive missing
evidence, resolve the separate inference epic, or authorize merge.

---
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Reliability**
* E2E checks can skip managed-image publication when selected checks
don’t require those images, while still enforcing publication for
dependent checks.
* Protected runtime checks verify candidate image artifacts and use
reviewed OpenShell sources and SDK versions.
* Admin approval selection errors now produce specific diagnostics
without exposing sensitive details.
* **Compatibility**
* OpenShell gateway checks resolve the version from the selected
candidate rather than relying on a fixed version.
* **Documentation**
* Added guidance on managed-image handling, E2E prerequisites, and
protected runtime checks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant