fix(onboard): add Jetson render device group - #7762
Conversation
Signed-off-by: J. Yaunches <jmyaunch@gmail.com>
📝 WalkthroughWalkthroughJetson GPU group detection now scans Tegra and DRI render devices, validates character-device access and GIDs, and propagates all eligible groups during sandbox recreation. Tests, end-to-end assertions, logging, and documentation cover the expanded device-node handling. ChangesJetson GPU group propagation
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant JetsonHost
participant detectTegraDeviceGroupGids
participant dockerRunDetached
participant SandboxUser
JetsonHost->>detectTegraDeviceGroupGids: enumerate GPU device paths
detectTegraDeviceGroupGids->>JetsonHost: inspect GID and permission mode
detectTegraDeviceGroupGids-->>dockerRunDetached: eligible group IDs
dockerRunDetached->>SandboxUser: apply --group-add entries
SandboxUser-->>dockerRunDetached: initialize CUDA as non-root
Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/lib/onboard/docker-gpu-jetson-groups.test.ts`:
- Around line 58-60: Update the filesystem spy-backed assertions in the affected
test cases to use try/finally, calling mockRestore() for each locally created fs
spy in the finally block. Apply this to the lstatSync spy and the additional spy
setups covering the indicated assertion ranges, ensuring cleanup occurs even
when an assertion fails.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 211e7ddb-d7f8-449a-bbd7-9c39df2002d9
📒 Files selected for processing (7)
docs/reference/commands.mdxdocs/reference/troubleshooting.mdxsrc/lib/onboard/docker-gpu-jetson-groups.test.tssrc/lib/onboard/docker-gpu-jetson-groups.tssrc/lib/onboard/docker-gpu-patch-jetson.test.tssrc/lib/onboard/docker-gpu-patch-recreate.tssrc/lib/onboard/docker-gpu-patch-types.ts
|
🌿 Preview your docs: https://nvidia-preview-pr-7762.docs.buildwithfern.com/nemoclaw |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit 75a9542 in the TypeScript / code-coverage/cliThe overall coverage in commit 75a9542 in the Show a code coverage summary of the most impacted files.
Updated |
PR Review Advisor — No blocking findings reportedAdvisor assessment: No blocking advisor findings reported Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
Signed-off-by: J. Yaunches <jmyaunch@gmail.com>
Signed-off-by: J. Yaunches <jmyaunch@gmail.com>
Signed-off-by: J. Yaunches <jmyaunch@gmail.com>
Signed-off-by: J. Yaunches <jmyaunch@gmail.com> # Conflicts: # test/e2e/support/e2e-report-to-pr-workflow-boundary.test.ts
<!-- markdownlint-disable MD041 --> ## Summary Add the canonical dated changelog entry for NemoClaw v0.0.97 before the release plan captures `origin/main`. The entry groups the user-visible and maintainer-facing changes since v0.0.96 while preserving the Deferred dual-Station status, experimental runtime-identity boundary, and pending physical IGX validation. ## Changes - Add `docs/changelog/2026-07-28.mdx` with the parser-safe MDX SPDX comment and exact `## v0.0.97` heading. - Summarize the 43 merged PRs in the release range, omitting internal-only changes from the public entry and linking each grouped change to its most specific published documentation. - Keep the experimental Okta reference explicitly opt-in and outside normal onboarding, keep the two-Station path Deferred, and state that physical IGX Orin validation remains pending. ### Source summary - [#7440](#7440), [#7443](#7443), and [#7445](#7445) -> `docs/changelog/2026-07-28.mdx`: Document read-only host readiness reports and fail-closed platform qualification. - [#7030](#7030) -> `docs/changelog/2026-07-28.mdx`: Document the Deferred trusted two-Station vLLM evaluation. - [#7265](#7265) -> `docs/changelog/2026-07-28.mdx`: Document the bounded experimental direct-runner Okta runtime-identity reference. - [#7711](#7711) and [#7648](#7648) -> `docs/changelog/2026-07-28.mdx`: Document compatible-endpoint reasoning effort and retired NVIDIA Build model paths. - [#7746](#7746), [#7763](#7763), and [#7681](#7681) -> `docs/changelog/2026-07-28.mdx`: Document safe compatible-provider creation, replacement refusal, and narrow OpenShell bridge URL handling. - [#7641](#7641), [#7690](#7690), [#7631](#7631), and [#7710](#7710) -> `docs/changelog/2026-07-28.mdx`: Document paused-container recovery, recreation journaling, pre-mutation uninstall checks, and source-checkout OpenShell selection. - [#7624](#7624) and [#7762](#7762) -> `docs/changelog/2026-07-28.mdx`: Document Jetson release diagnostics and bounded render-device group propagation. - [#7639](#7639), [#7760](#7760), [#7721](#7721), and [#7761](#7761) -> `docs/changelog/2026-07-28.mdx`: Document Telegram, MCP media-type, Hermes image-mode, and locked-restart fixes. - [#7653](#7653) and [#7680](#7680) -> `docs/changelog/2026-07-28.mdx`: Document Deep Agents policy tasks and the bounded Claude Code OAuth path. - [#7679](#7679) -> `docs/changelog/2026-07-28.mdx`: Document the checksum-bound libssh2 and Python HTMLParser backports. - [#7655](#7655), [#7651](#7651), [#7664](#7664), [#7666](#7666), [#7670](#7670), [#7719](#7719), and [#7741](#7741) -> `docs/changelog/2026-07-28.mdx`: Document exact candidate E2E evidence, Launchable selection, diagnostic consolidation, and trusted WSL validation. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates the dated changelog contract, MDX header, heading uniqueness, and release-entry structure. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: The committed `docs/changelog/2026-07-28.mdx` blob exactly matches the reviewed file. Completeness, factual accuracy, link shape, parser-safe MDX header, one-sentence-per-line style, `.docs-skip` compliance, and bounded product claims passed. - Agent: Codex Desktop documentation writer subagent <!-- docs-review-head-sha: da6aa27 --> <!-- docs-review-agents-blob-sha: be20a09 --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable; this PR changes only the dated changelog. - Station profile/scenario: Not applicable. - Result: Not applicable. - Supporting evidence: Not applicable. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts` passed 6/6. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — not applicable to this doc-only release entry. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — completed with 0 errors and 2 pre-existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — native changelog entries use the required parser-safe MDX SPDX comment and intentionally have no frontmatter. --- Signed-off-by: Charan Jagwani <cjagwani@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added improved host readiness reporting and Jetson onboarding guidance. * Added controls for reasoning effort with compatible endpoints and enhanced managed MCP discovery. * Improved Deep Agents task publication and preset support. * **Bug Fixes** * Hardened provider switching, sandbox recovery, uninstall behavior, and Telegram connectivity. * Improved container image integrity checks, media-type handling, and checksum validation. * Enhanced vLLM evaluation behavior and release diagnostics. * **Documentation** * Added the NemoClaw v0.0.97 changelog. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Summary
Jetson GPU onboarding now carries the eligible host group ID for real DRI render devices into the recreated Docker container. This gives the non-root sandbox user the additional device-group access required for CUDA initialization on the reported IGX Orin setup while preserving the existing Tegra device allowlist.
Related Issue
Fixes #7610
Changes
/dev/dri/renderD*character devices and reject symlinks.0440 root:video/dev/nvmapbehavior from [Jetson Orin][CLI&UX] nemoclaw status shows "Sandbox GPU: enabled" but CUDA is unusable inside sandbox — misleading status #4231.--group-addrecreation path.The root-cause hypothesis is that the reporter already receives the video/Tegra groups but not the distinct render-device owner GID. NVIDIA's Jetson container guidance identifies both video and render group membership as required for non-root CUDA initialization. The implementation intentionally does not scan DRI card nodes, arbitrary Tegra subtrees, or symlink targets.
No matching Jetson/IGX runner is currently available, so physical IGX Orin validation remains pending. The sandbox CUDA proof remains fail-closed and will reject the recreation if this best-guess fix is insufficient.
Type of Change
Quality Gates
0440 /dev/nvmapregression case.Documentation Writer Review
docs-updateddocs/reference/commands.mdx,docs/reference/troubleshooting.mdx, and the related CLI text, code comments, and test titles. The first review found inaccurate group-name and wildcard-scan wording; the final implementation review passed after the text was aligned with the bounded numeric-GID implementation. Follow-up reviews passed ate8dcfdb1eafter the CI-driven spy cleanup and helper JSDoc update, atbf46f3e13after aligning the live Jetson E2E assertion with the current stable group-propagation log prefix, and at75a954256after merging currentmain, retaining its 30-second E2E-support timeout, and confirmingnpm run docswith 0 Fern errors.DGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run check:diffpassed when hooks were skipped or unavailablenpm run typecheck:clipasses. The live-E2E assertion repair passed Biome and hook checks; the hardware-mutating Jetson E2E remains delegated to the repository's self-hosted gate. After merging currentmain, the E2E report boundary tests pass 33/33 with the upstream 30-second test-local timeout, andnpm run docspasses with 0 Fern errors.npm testfor broad runtime/test-harness changes;npm run checkfor repo-wide validation/coverage changes — command/result: Not applicable; the change is isolated to Jetson device-group discovery and propagation.npm run docsbuilds without warnings (doc changes only)npm run docspasses with 0 errors and the two existing Fern warnings.Signed-off-by: J. Yaunches jmyaunch@gmail.com