fix(installer): accept the current mode-bound Station Express resume receipt (#8205) - #8208
Conversation
…receipt (#8205) scripts/install.sh save_station_express_resume writes a ten-field receipt ending in `mode=`, but readStationExpressInstallerResumeGeneration only accepted the legacy three-field, agent-bound six-field, and port-bound nine-field formats. After a reboot/relogin continuation, completeSession() therefore rejected the installer's own current receipt with "DGX Station Express installer resume state is malformed" — even though the deployment was fully healthy and printed "OpenClaw is ready". Add a mode-bound format branch that accepts the exact ten-field receipt (the nine port-bound fields plus `mode=<express|provider>`, matching validate_station_install_mode in install.sh), while still accepting the legacy formats and rejecting an unknown/expanded mode. Add tests that write the current installer receipt and assert the production parser accepts it (and rejects an unknown mode), coupling the writer and parser contracts so they cannot drift again. Signed-off-by: Jason Ma <jama@nvidia.com> Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit 77cc677 in the TypeScript / code-coverage/cliThe overall coverage in commit 77cc677 in the Show a code coverage summary of the most impacted files.
Updated |
📝 WalkthroughWalkthroughStation Express resume validation now accepts exact mode-bound receipts with ChangesStation Express receipt handling
Estimated code review effort: 2 (Simple) | ~10 minutes Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/lib/onboard/station-express-resume.test.ts`:
- Around line 654-669: Add a separate public-boundary acceptance test alongside
the existing ten-field receipt test that writes modeReceiptText("provider") and
verifies assertStationExpressInstallerResumeMatches does not throw. Keep the
test focused on provider-mode behavior and use the same temporary
HOME/state-directory setup and cleanup without asserting implementation details.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 5e41318a-fc83-4ac2-9e17-7d4e0030b610
📒 Files selected for processing (2)
src/lib/onboard/station-express-resume.test.tssrc/lib/onboard/station-express-resume.ts
PR Review Advisor — No blocking findings reportedAdvisor assessment: No blocking advisor findings reported Model lanes
2 terminology differences from the second opinionAdvisory only. These are normalized differences from the primary terminology receipt.
3 additional E2E selections from the second opinionAdvisory only. The primary lane did not select these E2E jobs or targets.
Second-opinion terminology and E2E selections are advisory. They do not change the primary assessment or E2E / PR Gate. 2 semantic terminology decisionsTerminology decisions are advisory. They affect the assessment only when a separate finding identifies concrete semantic impact.
E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
cv
left a comment
There was a problem hiding this comment.
Reviewed the exact two-file diff and compared the parser values with validate_station_install_mode() in scripts/install.sh. The new shape remains strict about line count, field names, agents, sandbox name, policy tier, ports, mode, revision, model, and generation. I found no credential, injection, authorization, dependency, logging, cryptography, configuration, or privilege regression.
The CodeRabbit request for a separate provider acceptance test is reasonable additional contract coverage but is not a correctness blocker: express and provider use the same Set.has path, the current acceptance test exercises the ten-field shape, and the unknown-value test exercises rejection.
I cannot approve this SHA because both Advisor jobs failed, the required E2E gate is cancelled, and the branch is behind current main. Refresh it, obtain current required checks, and add the final documentation-writer review receipt with no-docs-needed evidence if the independent review confirms this internal receipt fix has no documentation impact.
cv
left a comment
There was a problem hiding this comment.
Reviewed commit d701132e0a. The only change after the prior receipt-parser review is the main merge. The ten-field mode shape remains strict and matches the installer writer; no code defect was found.
Approval is blocked by the shared main capability-union failure tracked by #8213, failed required E2E/CI, and a documentation-writer receipt that must identify this commit.
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
senthilr-nv
left a comment
There was a problem hiding this comment.
No blocking findings. The parser accepts only the exact mode-bound receipt shape, preserves legacy compatibility, rejects unknown modes, and the installer contract tests cover both express and provider using the real writer and public parser. CI is green. Approved.
<!-- markdownlint-disable MD041 --> ## Summary Prepares the canonical v0.0.102 release documentation from the current release-labeled scope. The change adds a dated changelog for all 38 user-facing shipping PRs and corrects the OpenClaw agent command reference for the behavior delivered by #8191. ## Changes - Add `docs/changelog/2026-08-04.mdx` with the v0.0.102 release summary, detailed behavior changes, support boundaries, security evidence links, and links to durable documentation. - Update `docs/reference/commands.mdx` to describe non-JSON OpenClaw output capture, its combined limit, marker handling, stream suppression, recovery guidance, and exit behavior. - [#8167](#8167) -> `docs/changelog/2026-08-04.mdx`: Records authenticated attachment of operator-managed llama.cpp servers. - [#8129](#8129) -> `docs/changelog/2026-08-04.mdx`: Records the Experimental managed vLLM profile for two DGX Spark systems. - [#7983](#7983) -> `docs/changelog/2026-08-04.mdx`: Records qualification of the May 2026 GB300WS factory image. - [#8207](#8207) -> `docs/changelog/2026-08-04.mdx`: Records the qualified DGX Station driver transaction. - [#8208](#8208) -> `docs/changelog/2026-08-04.mdx`: Records mode-bound Express resume state. - [#8158](#8158) -> `docs/changelog/2026-08-04.mdx`: Records recovery of host-global dual-Station runtime ownership. - [#8145](#8145) -> `docs/changelog/2026-08-04.mdx`: Records Windows-host Ollama validation from Docker Desktop's network context. - [#8190](#8190) -> `docs/changelog/2026-08-04.mdx`: Records HTTP model pulls when WSL has no local Ollama executable. - [#8195](#8195) -> `docs/changelog/2026-08-04.mdx`: Records reuse of a healthy installer-managed CLI. - [#8053](#8053) -> `docs/changelog/2026-08-04.mdx`: Records early rejection of incompatible OpenShell gateway versions. - [#8098](#8098) -> `docs/changelog/2026-08-04.mdx`: Records the bounded package-service-to-standalone gateway recovery transition. - [#8216](#8216) -> `docs/changelog/2026-08-04.mdx`: Records the final dashboard port selected during multi-sandbox onboarding. - [#8146](#8146) -> `docs/changelog/2026-08-04.mdx`: Records managed startup-state restoration for stopped sandboxes. - [#8092](#8092) -> `docs/changelog/2026-08-04.mdx`: Records gateway watchdog recovery for classified not-serving states. - [#8182](#8182) -> `docs/changelog/2026-08-04.mdx`: Records consistent managed-recovery wait configuration. - [#8040](#8040) -> `docs/changelog/2026-08-04.mdx`: Records Docker sandbox rollback authority through late validation. - [#8130](#8130) -> `docs/changelog/2026-08-04.mdx`: Records bounded Shields deadline recovery and durable containment. - [#8086](#8086) -> `docs/changelog/2026-08-04.mdx`: Records repair of narrowly validated permission-only configuration drift. - [#8122](#8122) -> `docs/changelog/2026-08-04.mdx`: Records prompt failure and guidance for corrupt transition locks. - [#8124](#8124) -> `docs/changelog/2026-08-04.mdx`: Records policy restoration flags, previews, and target revalidation. - [#7886](#7886) -> `docs/changelog/2026-08-04.mdx`: Records explicit destruction after pre-delete Shields hardening failures while preserving recovery authority. - [#7901](#7901) -> `docs/changelog/2026-08-04.mdx`: Records multi-port uninstall behavior and shared-resource preservation. - [#7984](#7984) -> `docs/changelog/2026-08-04.mdx`: Records one classified transient remote MCP startup retry. - [#7954](#7954) -> `docs/changelog/2026-08-04.mdx`: Records bounded hosted-inference probe replies. - [#7574](#7574) -> `docs/changelog/2026-08-04.mdx`: Records preservation of validated reasoning capabilities through onboarding. - [#8089](#8089) -> `docs/changelog/2026-08-04.mdx`: Records proxy routing for Hermes WhatsApp pairing and media traffic. - [#7682](#7682) -> `docs/changelog/2026-08-04.mdx`: Records native Hermes session deletion and identifier validation. - [#8150](#8150) -> `docs/changelog/2026-08-04.mdx`: Records corporate CA trust for LangChain Deep Agents Code image builds. - [#8156](#8156) -> `docs/changelog/2026-08-04.mdx`: Records reviewed managed runtime dependency remediation. - [#8180](#8180) -> `docs/changelog/2026-08-04.mdx`: Records reviewed MCP discovery runtime dependency updates. - [#8196](#8196) -> `docs/changelog/2026-08-04.mdx`: Records private npm dependency remediation across managed images. - [#8203](#8203) -> `docs/changelog/2026-08-04.mdx`: Records reviewed Hermes and LangChain Deep Agents Code Python dependency updates. - [#8125](#8125) -> `docs/changelog/2026-08-04.mdx`: Records bounded diagnostics for invalid enumerated CLI values. - [#8193](#8193) -> `docs/changelog/2026-08-04.mdx`: Records bounded diagnostics for unresolved sandbox base images. - [#8118](#8118) -> `docs/changelog/2026-08-04.mdx`: Records bounded diagnostics for changed gateway authority. - [#8191](#8191) -> `docs/changelog/2026-08-04.mdx`, `docs/reference/commands.mdx`: Records output capture, marker handling, recovery guidance, and exit behavior for non-JSON OpenClaw agent commands. - [#8187](#8187) -> `docs/changelog/2026-08-04.mdx`: Records the aligned interactive-installation start across supported agents. - [#8153](#8153) -> `docs/changelog/2026-08-04.mdx`: Records current product capabilities and support boundaries. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [x] Tests not applicable — justification: This documentation-only release preparation does not change executable behavior. Existing changelog and published-route tests pass. - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: Independently reviewed `docs/changelog/2026-08-04.mdx` and `docs/reference/commands.mdx` at commit `b89913780`. All 38 user-facing v0.0.102 PRs are represented, #8191 behavior matches the implementation, and the writing rules, documentation style, controlled terminology, route structure, and skip policy pass review. Targeted tests pass 36/36 and the documentation build completes with 0 errors. - Agent: Codex Desktop independent documentation writer <!-- docs-review-head-sha: b899137 --> <!-- docs-review-agents-blob-sha: 3dd7c24 --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable - Station profile/scenario: Not applicable - Result: Not applicable - Supporting evidence: Not applicable ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run validate:pr` passed after refreshing `origin/main` when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run --project integration test/changelog-docs.test.ts test/check-docs-published-routes.test.ts` passed 36/36. - [x] Applicable broad gate passed — not applicable to documentation-only changes; `npm run docs` completed successfully with 0 errors. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — completed with 0 errors and 2 existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [x] New doc pages include SPDX header and frontmatter (new pages only) — the native dated changelog uses the required parser-safe MDX SPDX comment and intentionally has no frontmatter. --- Signed-off-by: Apurv Kumaria <akumaria@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Added release notes for v0.0.102, covering authentication, hardware setup, WSL, installer recovery, sandbox resilience, policy management, inference reliability, CLI improvements, and unified quickstarts. - Updated command documentation to explain how non-JSON agent output is collected, replayed, and reported. - **Bug Fixes** - Improved command-output recovery guidance when output exceeds limits or contains unsupported fallback markers. - Preserved accurate command exit-status reporting after output processing. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Summary
DGX Station Express writes a mode-bound resume receipt before host preparation, but the onboarding completion parser rejected that same receipt after a reboot/relogin continuation. The deployment could become fully healthy and print
OpenClaw is ready, then exit nonzero while completing the session with:Cause:
scripts/install.shsave_station_express_resumewrites a ten-field receipt ending inmode=%s(install.sh:3975), butreadStationExpressInstallerResumeGeneration()only accepted the legacy three-field, agent-bound six-field, and port-bound nine-field formats. The ten-field mode-bound receipt (split("\n")→ 11 elements) matched no branch, socompleteSession()could not validate and retire the receipt the installer itself wrote.Fixes #8205.
Changes
src/lib/onboard/station-express-resume.ts: add amodeFormatbranch toreadStationExpressInstallerResumeGeneration()that accepts the exact ten-field receipt—the nine port-bound fields plusmode=<express|provider>, withSTATION_EXPRESS_RECEIPT_MODESmirroringvalidate_station_install_mode()ininstall.sh. Legacy formats stay accepted; an unknown or expanded mode is still rejected.src/lib/onboard/station-express-resume.test.ts: retain focused parser rejection coverage for an unknown mode without duplicating the installer's accepted receipt format.test/install-station-resume-cleanup.test.ts: exercise the realsave_station_express_resumewriter and production parser together for bothexpressandprovider, and verify that writer/parser field drift is rejected.Verification
Run on the Ubuntu host (
npm ci+ plugin build, Node 22), against a clean clone of this branch:npm run typecheck:cli→ exit 0.npx vitest run --project cli src/lib/onboard/station-express-resume.test.ts -t "mode-bound"→ 2 passed (accept current receipt; reject unknown mode).npx vitest run --project cli src/lib/onboard/station-express-resume.test.ts→ 63 passed.Error: DGX Station Express installer resume state is malformed.—the exact reported failure.Additional contract validation for the Advisor finding:
git diff --checkpassed.Documentation
No user-visible surface change. This is an internal installer-resume receipt contract, and the behavior is corrected so a healthy Station Express deployment no longer fails at session completion. No documentation update is required.
Documentation Writer Review
no-docs-neededSigned-off-by: Jason Ma jama@nvidia.com
Summary by CodeRabbit
New Features
expressorprovidermodes.Bug Fixes