fix(ci): select DCode E2E for runtime changes - #7517
Conversation
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
📝 WalkthroughWalkthroughDeep Agents Code runtime changes now select typed E2E targets, with risk-plan version 6, updated invariants, tests, and gate documentation. The Hermes Dockerfile also updates its pinned sandbox base-image digest. ChangesDeep Agents Code risk targeting
Hermes base image
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related issues
Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit ed8eab5 in the TypeScript / code-coverage/cliThe overall coverage in commit ed8eab5 in the Show a code coverage summary of the most impacted files.
Updated |
VerdictPASS. I reviewed exact head FindingsNo security findings. Detailed analysis
Files reviewed
|
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
tools/advisors/risk-plan.mts (1)
125-136: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winAdd regression coverage for the headless and
.mdxbranches.The new test covers a runtime-file match and a
.mdexclusion, but not the exact headless-inference path or.mdxexclusion introduced here. Add behavioral cases asserting both outcomes.As per path instructions, advisor logic must have focused tests for both detection and false-positive behavior.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@tools/advisors/risk-plan.mts` around lines 125 - 136, Add focused regression tests for the matching logic that produces matchedFiles: verify DEEPAGENTS_HEADLESS_INFERENCE_CHECK is detected, and verify files ending in .mdx under DEEPAGENTS_CODE_RUNTIME_ROOT are excluded. Keep the existing runtime-file detection and .md exclusion coverage, and assert both detection and false-positive outcomes.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@test/e2e/README.md`:
- Around line 462-464: Update the fork-revision guidance in the correlated
workflow documentation to apply only when the plan selects credential-bearing
E2E jobs or targets. State that such fork revisions require explicit
credentialed-E2E skip approval, while plans with no selected jobs or targets can
complete without an E2E run.
---
Nitpick comments:
In `@tools/advisors/risk-plan.mts`:
- Around line 125-136: Add focused regression tests for the matching logic that
produces matchedFiles: verify DEEPAGENTS_HEADLESS_INFERENCE_CHECK is detected,
and verify files ending in .mdx under DEEPAGENTS_CODE_RUNTIME_ROOT are excluded.
Keep the existing runtime-file detection and .md exclusion coverage, and assert
both detection and false-positive outcomes.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 9cbe04b8-72d5-4cb4-8620-4f9bc11e243a
📒 Files selected for processing (4)
test/e2e/README.mdtest/pr-e2e-gate-fork-skip.test.tstest/pr-risk-plan.test.tstools/advisors/risk-plan.mts
PR Review Advisor — No blocking findings reportedAdvisor assessment: No blocking advisor findings reported Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: 1 optional E2E recommendation
This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
Security review for Result: PASS — no security findings.
The follow-up commit narrows selection with the repository's existing runtime-relevance predicate, so test-only and documentation-only changes under the DCode directory do not gain unnecessary credentialed E2E access. |
prekshivyas
left a comment
There was a problem hiding this comment.
Reviewed exact head 9dd1c973c61c6dd2959c880489635fe015994107 against base 2f6298ee165f4821f635be962fedff5e165701ee.
Verdict: PASS — no findings.
- The deterministic controller now maps runtime-relevant changes under
agents/langchain-deepagents-code/to the existing allowlistedubuntu-repo-cloud-langchain-deepagents-codetarget. - The shared runtime predicate excludes documentation, MDX, ordinary test directories, and
*.test.*or*.spec.*files. - The selector cannot introduce an arbitrary target; dispatch still validates the compile-time target allowlist and exact PR/base SHAs.
- Protected authorization, controller-side plan reconstruction, plan hashing, trusted workflow dispatch, and bound evidence validation remain unchanged.
- Regression coverage includes #7463's exact changed-file set, the existing headless-inference selector, Markdown/MDX/test-only exclusions, and the fork approval path.
All nine sensitive-path security categories pass. Ordinary CI, CodeQL, CodeRabbit, and both PR Advisor lanes are clean. The one unrelated CLI test timeout passed on rerun.
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
prekshivyas
left a comment
There was a problem hiding this comment.
Reviewed exact head 6373d3db4e7985befa1697c98c73d7107faf20d8 against base d4a859a886f36da3ecf953edf6b5121c1ea84842.
Verdict: PASS — no findings. The current-main refresh carries already-merged repository fixes; the only PR-specific delta since the prior security review corrects the fork-controller regression to assert the selected targets: evidence for a target-only plan. The original risk-plan change still narrows matching to one compile-time allowlisted DCode target, excludes docs and ordinary tests, rebuilds the plan in the trusted controller, and preserves protected authorization plus exact head/base binding.
Nine-category result:
- Secrets and credentials — PASS: no credentials or secret values added; protected fork authorization remains required.
- Input validation and sanitization — PASS: changed paths are matched by fixed exact/prefix predicates and targets remain compile-time allowlisted.
- Authentication and authorization — PASS: no authorization bypass; runtime changes now enter the protected approval path.
- Dependencies — PASS: no PR dependency change.
- Error handling and logging — PASS: summaries expose only deterministic plan metadata and SHAs.
- Cryptography and data protection — PASS: no cryptographic change; existing SHA-bound plan hashing remains intact.
- Configuration and security headers — PASS: no runtime configuration or network exposure change.
- Security testing — PASS: focused tests cover DCode selection, docs/test exclusions, and the fork protected-approval path; four exact integration files passed 125 tests.
- System security — PASS: the change strengthens fail-closed E2E coverage and cannot select arbitrary jobs or targets.
Files reviewed: tools/advisors/risk-plan.mts, test/pr-risk-plan.test.ts, test/pr-e2e-gate-fork-approval.test.ts, and test/e2e/README.md.
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
prekshivyas
left a comment
There was a problem hiding this comment.
Exact-head nine-category security review for 13efac6d67a133bb2b4395d14e5c0b6dd534c419 against base d4a859a886f36da3ecf953edf6b5121c1ea84842.
- Input and data validation — PASS. Runtime path matching is bounded to the declared Deep Agents Code root, excludes documentation and ordinary tests, and emits only the compile-time allowlisted typed target.
- Authentication and authorization — PASS. Risk selection does not grant credentials; risky fork execution still requires protected exact-revision authorization, and the corrected guide now states that approval authorizes execution rather than a skip.
- Secrets and sensitive data — PASS. No secret values, new secret sources, or credential logging are introduced. Selected fork code remains behind the trusted controller boundary.
- Injection and command execution — PASS. The change adds static path classification and an immutable image digest only; it does not interpolate changed paths into shell or generated code.
- Network and SSRF — PASS. No new endpoint or request path is introduced. The Hermes image reference is digest-bound under the existing NVIDIA GHCR namespace.
- Filesystem and state boundaries — PASS. No new filesystem mutation, privilege transition, or state recovery behavior is added.
- Dependencies and supply chain — PASS. The Hermes pin is the immutable digest published by trusted base-image workflow run 30195335992 from current-main dependency remediation; it replaces the stale pre-remediation image instead of using a mutable tag.
- Concurrency, replay, and exact identity — PASS. Risk plan version 6 changes the plan hash, retains stable unique inputs, and the controller continues to bind PR head, base, target allowlist, plan, and child run.
- Tests and fail-closed behavior — PASS. Target selection, docs/tests exclusion, target-only authorization summaries, and deterministic plan hashing are covered. Focused selection produced 97 passing tests with one unrelated existing temp-cleanup fixture failure; normal commit and push hooks passed.
Disposition: PASS. No correctness or security findings.
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
Exact-head nine-category security review for local commit
Disposition: PASS. No correctness or security findings. |
<!-- markdownlint-disable MD041 --> ## Summary Add the canonical `docs/changelog/2026-07-25.mdx` release entry with the exact `## v0.0.96` heading. The entry reconciles all 90 first-parent commits since v0.0.95 with all 92 merged PRs in the live `v0.0.96` label ledger and groups the user-visible changes by operator journey. ## Changes - Add the parser-safe dated MDX changelog entry for v0.0.96 with root-absolute links to the focused user guides. - Source summary: - [#7194](#7194) -> `docs/changelog/2026-07-25.mdx`: Document persistent baseline network policy exclusions and their inspection, rebuild, and snapshot behavior. - [#7188](#7188), [#7427](#7427), and [#7546](#7546) -> `docs/changelog/2026-07-25.mdx`: Document DNS-backed HTTPS inference routing, keyless loopback endpoints, and provider-marker isolation. - [#7238](#7238) -> `docs/changelog/2026-07-25.mdx`: Document blueprint sandbox and provider identifier validation before state writes or OpenShell calls, with bounded terminal-safe rejection previews. - [#7319](#7319), [#7274](#7274), [#7528](#7528), [#7353](#7353), and [#7560](#7560) -> `docs/changelog/2026-07-25.mdx`: Document the managed default gateway service, onboarding readiness, and container-runtime identity safeguards. - [#7349](#7349), [#7498](#7498), [#7406](#7406), [#7196](#7196), [#7559](#7559), [#7421](#7421), [#7510](#7510), [#7295](#7295), and [#7565](#7565) -> `docs/changelog/2026-07-25.mdx`: Document gateway-scoped status, lifecycle diagnostics, managed MCP recovery, delete-edge safeguards, and fail-closed CLI prompt and command output. - [#7591](#7591) -> `docs/changelog/2026-07-25.mdx`: Document opt-in authenticated MCP tool-name discovery, its bounded and names-only contract, probe interaction, and rebuild requirement. - [#7305](#7305), [#7480](#7480), [#7471](#7471), [#7365](#7365), and [#7541](#7541) -> `docs/changelog/2026-07-25.mdx`: Document installer version checks, version-tag reporting, license guidance, WSL Ollama selection, and DGX Station vLLM detection. - [#7482](#7482), [#7466](#7466), [#7208](#7208), [#7434](#7434), and [#7586](#7586) -> `docs/changelog/2026-07-25.mdx`: Document Ollama resource details, reasoning precedence, Hermes onboarding behavior, and preserved managed Hermes BuildKit failures. - [#6830](#6830), [#7492](#7492), [#7563](#7563), and [#7582](#7582) -> `docs/changelog/2026-07-25.mdx`: Document the authoritative OpenClaw production lock, fixed managed-image dependencies, immutable Hermes base adoption, and Hermes image-size reduction. - [#7505](#7505), [#7530](#7530), [#7547](#7547), [#7508](#7508), [#7548](#7548), [#7549](#7549), [#7537](#7537), [#7534](#7534), [#7515](#7515), [#7511](#7511), [#7551](#7551), [#7562](#7562), [#7575](#7575), [#7496](#7496), [#7594](#7594), [#7595](#7595), and [#7599](#7599) -> `docs/changelog/2026-07-25.mdx`: Summarize release validation, transient and bounded dispatch reconciliation, exact pre-tag qualification, identity revalidation, npm-audit retry, sharding, image reuse, timeout, telemetry, and workflow-hardening changes. - Reconciled without separate changelog prose: - [#7539](#7539), [#7526](#7526), [#7507](#7507), [#7506](#7506), [#7519](#7519), [#7516](#7516), [#7396](#7396), [#7254](#7254), [#7583](#7583), [#7596](#7596), and [#7598](#7598): Test-harness or fixture-only changes. - [#7403](#7403), [#7161](#7161), [#6877](#6877), [#7531](#7531), [#7525](#7525), [#7522](#7522), [#7536](#7536), [#7552](#7552), [#7566](#7566), [#7553](#7553), [#7561](#7561), [#7577](#7577), [#7569](#7569), [#7585](#7585), [#7584](#7584), [#7592](#7592), [#7580](#7580), [#7571](#7571), [#7517](#7517), [#7589](#7589), [#7402](#7402), [#7558](#7558), [#7544](#7544), and [#7601](#7601): Dependency, internal recovery, validation, contributor-workflow, E2E optimization, telemetry, or CI trust changes with no separate user-facing release claim. - [#7556](#7556), [#7573](#7573), [#7576](#7576), and [#7578](#7578): Experimental repository-maintainer conflict automation with no canonical user documentation surface. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates dated changelog structure, version headings, and published links. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: Reviewed `docs/changelog/2026-07-25.mdx` at exact head `0f5dedb47` against 90 first-parent release commits and 92 merged PRs labeled `v0.0.96`. Verified parser-safe MDX SPDX, the exact version heading, literal CLI names, writing style, skip terms, all 20 root-absolute published links, and the accepted #7591 opt-in authenticated discovery bounds. #7544, #7599, and #7601 remain internal or CI-only release-ledger entries. Changelog tests passed 6/6, the docs build passed with 0 errors and two pre-existing Fern warnings, and `npm run check:diff` plus the final diff check passed. - Agent: Codex Desktop documentation-writer subagent <!-- docs-review-head-sha: 0f5dedb --> <!-- docs-review-agents-blob-sha: be20a09 --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: - Station profile/scenario: - Result: - Supporting evidence: ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts`: 6/6 passed. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to this prose-only changelog entry. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — the build passed with 0 errors and 2 existing Fern warnings; the published-route check passed. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — native changelog files use the required parser-safe MDX SPDX comment and no frontmatter. --- Signed-off-by: Carlos Villela <cvillela@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Persistent network policy exclusions with consistent restore/exclusion reporting across rebuilds/snapshots. * Opt-in MCP tool discovery via `mcp status --tools` with bounded, redacted authenticated traffic. * Improved HTTPS inference switching for custom endpoints and refreshed onboarding/model menu details. * Refined OpenShell gateway defaults for port `8080`, including more reliable readiness checks. * **Bug Fixes** * Prevent incorrect provider/model restoration after compatible-provider update failures. * Preserve managed MCP state after exec loss and tighten gateway/doctor status scoping. * **Tests** * Stronger, fail-closed release validation with hardened evidence/artifact handoff and bounded timeouts/retries. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> Co-authored-by: Prekshi Vyas <prekshiv@nvidia.com>
Summary
Deep Agents Code runtime changes could produce an empty deterministic E2E plan even when the PR Review Advisor selected the existing DCode typed target. Risk-plan v6 now selects that target directly from trusted changed-file paths, so a fork revision cannot pass E2E coordination without entering the protected approval path.
Related Issue
Related to #7463
Changes
ubuntu-repo-cloud-langchain-deepagents-codefor non-documentation runtime changes underagents/langchain-deepagents-code/and for the existing headless-inference live check.test/e2e/README.md.Type of Change
Quality Gates
ed8eab5ed65f9bd539a0221aadf54a8de6705d91against basee833bd863f0b06be97bedaf5343188ee19923384with no findings; target selection remains allowlisted and exact-plan-bound, and the Hermes image is pinned to the trusted published remediation digest.Documentation Writer Review
docs-updatedtest/e2e/README.mdaccurately documents DCode runtime target selection, explicit protected credentialed-E2E approval for risky fork plans, and empty-plan behavior. The immutable Hermes digest refresh and conflict-free upstream retry-history merge require no additional user documentation. Changed text followsWRITING.md;git diff --checkpasses.DGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run check:diffpassed when hooks were skipped or unavailablenpm testfor broad runtime/test-harness changes;npm run checkfor repo-wide validation/coverage changes — command/result: Pull-request CI will provide the applicable broad gate.npm run docsbuilds without warnings (doc changes only)Signed-off-by: Prekshi Vyas prekshiv@nvidia.com
Summary by CodeRabbit