ci(installer): trust Homebrew formula transition - #7374
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (2)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughInstaller hash validation now supports the transitional ChangesInstaller hash transition
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant InstallerPins
participant TemplateVerifier
participant AssetSetValidator
participant ReleaseVerifier
participant OpenShellRelease
InstallerPins->>TemplateVerifier: validate installer template against trusted hashes
TemplateVerifier-->>InstallerPins: matched template SHA
InstallerPins->>AssetSetValidator: validate template-specific asset set
ReleaseVerifier->>OpenShellRelease: download openshell.rb
OpenShellRelease-->>ReleaseVerifier: formula payload
ReleaseVerifier->>ReleaseVerifier: compare computed digest with pinned value
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit 848dcfb in the TypeScript / code-coverage/cliThe overall coverage in commit 848dcfb in the Show a code coverage summary of the most impacted files.
Updated |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@scripts/checks/extract-installer-pins.mts`:
- Around line 175-184: Reject duplicate asset names in assertInstallerAssetSet
before selecting the expected 8-or-9 asset set, rather than relying on
assertExactAssetSet’s deduplicated comparison. Add a test fixture in
test/installer-hash-check.test.ts covering a duplicate archive pin and assert
that trusted verification rejects it.
In `@test/installer-hash-check.test.ts`:
- Around line 625-652: Extend the formula-specific sha256sum stub in the
installer hash test to support a mismatching-digest mode, while preserving the
existing successful FORMULA_DIGEST behavior. Add a test case that enables this
mode, invokes the direct-hash validation path, and asserts a nonzero result
containing STALE.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 10cdac1b-60b2-4cd1-9c8d-6942577cbf62
📒 Files selected for processing (3)
scripts/check-installer-hash.shscripts/checks/extract-installer-pins.mtstest/installer-hash-check.test.ts
PR Review Advisor — InformationalAdvisor assessment: Informational / high confidence Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: None 2 optional E2E recommendations
1 warning · 0 suggestionsWarningsWarnings do not block.
|
cjagwani
left a comment
There was a problem hiding this comment.
Approved after refreshing onto the current base and completing the exact-revision trust-boundary review. The checker accepts only two exact operational templates, maps each to an exact immutable asset set, rejects duplicate or malformed pins, and fails closed on manifest, formula, hash, and count errors. I also ran the trusted parser and live verifier against the dependent formula transition: all three manifests, eight archives, openshell.rb, and both Brev assets matched their pinned SHA-256 values. All 51 current checks are green, contributor compliance passes, and the advisor has no blocker; its formula-download regression warning is non-blocking because the reviewed branch uses the same bounded fetch_file failure path and returns the accumulated failure count.
<!-- markdownlint-disable MD041 --> ## Summary Adds the canonical `## v0.0.92` release entry to `docs/changelog/2026-07-22.mdx` before the release plan is generated. The entry summarizes all ten pull requests merged after v0.0.91, including the OpenClaw security update and Jaeger runtime regression coverage. ## Changes - Added the canonical v0.0.92 changelog entry. - Recorded the user-visible, security, documentation, CI, and test changes in the release range. - #7280 -> `docs/changelog/2026-07-22.mdx`: OpenClaw 2026.7.1 and Node.js 22.23.1 security/runtime update. - #7378 -> `docs/changelog/2026-07-22.mdx`: canonical macOS watcher path validation. - #7379 -> `docs/changelog/2026-07-22.mdx`: stabilized full WSL platform validation. - #7380 -> `docs/changelog/2026-07-22.mdx`: bounded swap for hosted Hermes image exports. - #7100 -> `docs/changelog/2026-07-22.mdx`: semantic progress phases for live E2E tests. - #7376 -> `docs/changelog/2026-07-22.mdx`: restored v0.0.91 changelog history and corrected tagged guidance. - #7374 -> `docs/changelog/2026-07-22.mdx`: reviewed Homebrew formula transition for installer integrity checks. - #7346 -> `docs/changelog/2026-07-22.mdx`: provider-neutral headless server deployment guidance. - #7381 -> `docs/changelog/2026-07-22.mdx`: stabilized Hermes guard timing and WSL ownership fixtures. - #7339 -> `docs/changelog/2026-07-22.mdx`: real-artifact Jaeger header remediation regression coverage. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates the canonical dated changelog and release heading contract. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable - Station profile/scenario: Not applicable - Result: Not applicable - Supporting evidence: Not applicable ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts` passed 6/6 tests. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to a changelog-only change. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — passed with 0 errors and 2 pre-existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Carlos Villela <cvillela@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added `v0.0.92` release notes covering sandboxing updates (OpenClaw/Node.js bumps, integrity pinning remediation, mcporter handling, and upgrade validation). * Updated deployment guidance for provider-neutral headless installs, and improved live E2E test reporting plus phase-plan validation. * Tightened installer integrity-check messaging during an OpenShell Homebrew transition and expanded platform/image validation (including macOS/WSL timing) and hosted image export behavior. * Restored the previously missed `v0.0.91` changelog entry and release validation guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Summary
Allow the base-trusted installer verifier to accept either the current archive-only installer template with its exact eight-asset table or the reviewed formula installer template with those same eight assets plus
openshell.rb. Each trusted template hash is bound to its exact asset set, so this prerequisite lets #7319 pass base-SHA verification without allowing a formula pin before its consumer or arbitrary release assets and templates.Related Issue
Refs #6903
Prerequisite for #7319.
Changes
openshell.rbuntil feat(gateway): manage the default gateway service #7319 lands and tightens the rule.Type of Change
Quality Gates
DGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run check:diffpassed when hooks were skipped or unavailablenpx vitest run --project integration test/installer-hash-check.test.ts(74 passed); the trusted checker also passed against this PR's archive-only installer, the actual feat(gateway): manage the default gateway service #7319 formula-consuming installer, and the OpenShell v0.0.85 release assets.npm testfor broad runtime/test-harness changes;npm run checkfor repo-wide validation/coverage changes — command/result:npm run checkcompleted every pre-commit gate successfully, then reached the 20-minute local timeout during the manual coverage stage.npm run docsbuilds without warnings (doc changes only)Signed-off-by: San Dang sdang@nvidia.com
Summary by CodeRabbit
openshell.rb).