You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: .agents/skills/launch-openshell-gator/SKILL.md
+12-18Lines changed: 12 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,7 +13,7 @@ For gator's PR/issue validation policy, load `gator-gate` inside the launched sa
13
13
14
14
## Non-Negotiable Rules
15
15
16
-
- Keep normal gator launches supervised: use `--watch --background` and let the in-sandbox supervisor own sleeping and relaunching bounded cycles.
16
+
- Keep normal gator launches supervised: use `--watch` and let the in-sandbox supervisor own sleeping and relaunching bounded cycles.
17
17
- Do not add passive `sleep` loops in the operator session to watch gator. Check logs or status once, then report the current state or launch a proper watcher outside the model session only when explicitly asked.
18
18
- Do not change the default gator model in `scripts/agents/gator/agent.yaml` for experiments. Use `CODEX_MODEL=...` and, if needed, a temporary `--from` Docker context or `--codex-bin` override.
19
19
- Do not push to contributor branches, approve, merge, post `/ok to test`, or broaden gator scope unless the operator explicitly authorized that action.
@@ -34,7 +34,6 @@ For gator's PR/issue validation policy, load `gator-gate` inside the launched sa
34
34
|`scripts/agents/gator/bin/validate-review-findings`| Enforces the blocker evidence schema and downgrades unsupported hypotheses. |
35
35
|`scripts/agents/gator/prompts/gator.md`| Rendered top-level prompt template baked into the payload. |
"Review and monitor PR #${pr_number} through the gator-gate workflow. Scope this invocation only to PR #${pr_number}."
161
159
```
162
160
163
-
The launcher queries gateway's selected compute driver, builds gator image in matching Docker or Podman image store, stages immutable payload, imports provider profiles, configures provider credentials and refresh, creates and uploads sandbox payload, then starts agent supervisor with `sandbox exec`. It writes a background log under `scripts/agents/gator/logs/`. `CONTAINER_ENGINE`, when set, must match gateway driver.
161
+
The launcher queries the gateway's selected compute driver, builds the gator image in the matching Docker or Podman image store, stages the immutable payload, imports provider profiles, configures provider credentials and refresh, and starts the agent supervisor as the sandbox's canonical main process. The detached main process survives loss of the host CLI connection and reconnects to a restarted gateway. Unless `--keep` is set, the sandbox is marked ephemeral so the gateway deletes it after the supervisor exits. `CONTAINER_ENGINE`, when set, must match the gateway driver.
162
+
163
+
The launcher streams image-build and provisioning output until the detached workload is ready, then exits. Use `openshell logs <sandbox-name>` or the TUI for runtime output.
"Review and monitor PR #${pr_number} with linked issue #${issue_number} through the gator-gate workflow. Scope this invocation only to PR #${pr_number} and issue #${issue_number}."
"Review and monitor PR #${pr_number} through the gator-gate workflow. Scope this invocation only to PR #${pr_number}. The operator explicitly authorizes applying the test:e2e label, posting /ok to test for the current head SHA, and rerunning the relevant current-head workflow when the E2E Label Help bot says that is required."
224
221
```
225
222
@@ -241,7 +238,6 @@ CODEX_MODEL=gpt-5.6-sol \
241
238
--gateway "$gateway_name" \
242
239
--name "$sandbox_name" \
243
240
--watch \
244
-
--background \
245
241
"Review and monitor PR #${pr_number} through the gator-gate workflow. Scope this invocation only to PR #${pr_number}. This launch is intentionally testing Codex model gpt-5.6-sol via the CLI launcher."
246
242
```
247
243
@@ -266,27 +262,22 @@ CODEX_MODEL=gpt-5.6-sol \
266
262
--name "$sandbox_name" \
267
263
--from "$tmp_context" \
268
264
--watch \
269
-
--background \
270
265
"Review and monitor PR #${pr_number} through the gator-gate workflow. Scope this invocation only to PR #${pr_number}."
271
266
```
272
267
273
268
## Monitoring
274
269
275
270
### Read The Launch Result
276
271
277
-
The launcher prints the log path when `--background` is used:
278
-
279
-
```text
280
-
Started in background. Log: scripts/agents/gator/logs/<sandbox-name>.log
281
-
```
282
-
283
-
Read that file directly. Important markers:
272
+
The launcher streams image-build and provisioning output to the terminal. Important markers:
284
273
285
274
-`Built image ...` means the local image build completed.
286
275
-`Created sandbox: <name>` means OpenShell accepted the sandbox.
287
276
-`openshell-agent: starting watch cycle` means the in-sandbox supervisor began a bounded cycle.
288
277
-`OpenAI Codex v...` plus `model: ...` confirms the Codex CLI and model actually used.
289
278
-`OPENSHELL_AGENT_RESULT {...}` is the bounded-cycle sentinel. In watch mode, the supervisor sleeps and relaunches after this line.
279
+
-`/sandbox/.openshell-agent/status.json` is the atomic current state snapshot. Its `result.notes` field is Gator's plain-language diagnosis and next action for that cycle.
280
+
-`/sandbox/.openshell-agent/history.jsonl` contains the latest 100 supervisor transitions, including active-cycle starts and completed cycle results.
290
281
-`openshell-agent: still running watch cycle ...` is a heartbeat during long active model cycles.
291
282
-`review_feedback_lookup_failed` means Gator could not build the required cross-SHA feedback ledger and deliberately skipped a context-free review.
292
283
@@ -314,6 +305,11 @@ If `sandbox get` is not supported by the local CLI shape, use `openshell sandbox
314
305
|`status=terminal_failure`| Unrecoverable or stale immutable payload. | Inspect the reason; rebuild/relaunch for `stale_gator_payload`. |
315
306
|`status=complete`| Target closed, merged, or one-shot complete. | Delete sandbox if no longer needed. |
316
307
308
+
Prefer the state snapshot over scraping transient `/tmp` cycle output. Use the
309
+
history file to tell whether a failure is repeating or whether the supervisor
310
+
has begun a fresh cycle. Runtime logs remain useful for full command output and
311
+
transport diagnostics.
312
+
317
313
## Restarting A Gator
318
314
319
315
Restart when the payload must change, the sandbox is wedged without a sentinel, the model/tooling version changed, or a transient failure repeats past the useful retry point.
Copy file name to clipboardExpand all lines: .agents/skills/sbom/SKILL.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,7 +15,7 @@ The OpenShell SBOM tooling produces source-tree CycloneDX JSON SBOMs using Syft,
15
15
16
16
SBOMs are **release artifacts only** -- they are generated on demand and not committed to the repository. Output lands in `deploy/sbom/output/` (gitignored).
17
17
18
-
Pushed gateway and supervisor images carry an SPDX SBOM and minimal SLSA provenance as OCI attestations. Branch E2E, Release Dev, and Release Tag image binaries embed cargo-auditable metadata, so their image SBOMs include linked Rust crates.
18
+
Pushed gateway, sandbox, and supervisor images carry an SPDX SBOM and minimal SLSA provenance as OCI attestations. Branch E2E, Release Dev, and Release Tag image binaries embed cargo-auditable metadata, so their image SBOMs include linked Rust crates.
| Gateway deployment, Helm, runtime drivers, or health checks |`debug-openshell-cluster`, `helm-dev-environment`|
48
-
| Inference providers, native model endpoints, or migration from `inference.local`|`debug-inference`, `openshell-cli`, `generate-sandbox-policy`|
48
+
| Inference providers, native model endpoints, or migration from the retired managed endpoint|`debug-inference`, `openshell-cli`, `generate-sandbox-policy`|
49
49
| TUI architecture, navigation, data fetching, or UX |`tui-development`|
50
50
| Release artifacts or post-publish smoke coverage |`test-release-canary`|
51
51
| GitHub Actions workflows, required checks, or CI diagnostics |`watch-github-actions`; also `test-release-canary` for release smoke coverage |
Copy file name to clipboardExpand all lines: .agents/skills/test-release-canary/SKILL.md
+13-9Lines changed: 13 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,18 +13,20 @@ The Release Canary (`.github/workflows/release-canary.yml`) smoke-tests the arti
13
13
14
14
| Job | Runner | Verifies |
15
15
|---|---|---|
16
-
|`macos`|`macos-latest-xlarge`|`install.sh` resolves the Homebrew formula, brew installs the cask, and `openshell status` reaches the brew-services–backed local gateway with the VM driver. |
17
-
|`ubuntu`|`ubuntu-latest`|`install.sh` installs the Debian package, the post-install systemd user service starts, and `openshell status` reaches the local gateway with the Docker driver. |
18
-
|`fedora`|`fedora:latest` container |`install.sh` installs the RPM packages, the local gateway starts under Podman, and `openshell status` succeeds. |
19
-
|`ubuntu-snap`|`ubuntu-latest`|Downloads the Snap artifact from Release Dev, installs it with `--dangerous`, connects the required interfaces, and waits up to 30 seconds for the recovered local gateway. |
20
-
|`kubernetes`|`ubuntu-latest` + kind |`helm install oci://ghcr.io/nvidia/openshell/helm-chart --version 0.0.0-dev` succeeds in a kind cluster, the gateway pod becomes Ready, port-forward exposes 8080, and the released CLI registers the in-cluster gateway and runs `openshell status` against it. |
16
+
|`macos`|`macos-latest-xlarge`|Installs the dev Homebrew artifacts, reaches the VM gateway, and creates, executes in, and deletes a sandbox. |
17
+
|`ubuntu`|`ubuntu-latest`|Installs the dev Debian package, reaches the Docker gateway, and creates, executes in, and deletes a sandbox. |
18
+
|`fedora`|`fedora:latest` container |Installs the dev RPM packages, reaches the Podman gateway, and creates, executes in, and deletes a sandbox. |
19
+
|`ubuntu-snap`|`ubuntu-latest`|Installs the Release Dev Snap, connects its interfaces, reaches the Docker gateway, and creates, executes in, and deletes a sandbox. |
20
+
|`kubernetes`|`ubuntu-latest` + kind |Installs the dev Helm chart, reaches the in-clustergateway, and creates, executes in, and deletes a sandbox using the published runtime images. |
21
21
22
22
All canary jobs disable anonymous OpenShell telemetry. Host package jobs inject
23
23
`OPENSHELL_TELEMETRY_ENABLED=false` through the service environment, and the
24
24
Kubernetes job installs with `server.telemetryEnabled=false`, so smoke traffic
25
25
does not contribute to product usage metrics.
26
26
27
-
`install.sh` defaults to the *latest tagged* release — the canary is therefore checking that the most recent public release still installs, not the just-published `dev` build. The `kubernetes` job is the exception: it pins to `0.0.0-dev` chart + `:dev` images.
27
+
The workflow sets `OPENSHELL_VERSION=dev`, so every `install.sh` job consumes the
28
+
rolling dev release produced by the triggering workflow. Kubernetes pins the
29
+
matching `0.0.0-dev` chart and `:dev` images.
28
30
29
31
The host-package jobs exercise fresh installs, not upgrades from a persisted
30
32
schema-v1 gateway config. Validate Homebrew and RPM exact-default migration with
@@ -83,7 +85,7 @@ gh run view <run-id> --log-failed
83
85
84
86
## Iterating on the canary itself
85
87
86
-
When you change `release-canary.yml` on a branch, a manual dispatch on that branch tests *your branch's workflow logic* against *main's published artifacts* (`0.0.0-dev` chart, `:dev` images, latest tagged install.sh assets). This is what you want for iterating on the canary — you're validating that the canary still works against known-good artifacts.
88
+
When you change `release-canary.yml` on a branch, a manual dispatch on that branch tests *your branch's workflow logic* against *main's published dev artifacts* (`0.0.0-dev` chart, `:dev` images, and the `dev` GitHub release). This is what you want for iterating on the canary — you're validating that the canary still works against known-good artifacts.
87
89
88
90
Note `install.sh` is pulled from `raw.githubusercontent.com/NVIDIA/OpenShell/${head_sha}/install.sh`, so changes to `install.sh` on your branch *are* exercised even though the binaries it downloads are from the latest public tag.
89
91
@@ -92,7 +94,7 @@ Note `install.sh` is pulled from `raw.githubusercontent.com/NVIDIA/OpenShell/${h
92
94
`Release Dev` publishes two chart versions for every dev build (see `.github/actions/release-helm-oci/action.yml:89-102`):
93
95
94
96
- `oci://ghcr.io/nvidia/openshell/helm-chart:0.0.0-dev`— floating, overwritten on every main push.
95
-
- `oci://ghcr.io/nvidia/openshell/helm-chart:0.0.0-dev.<sha>`— immutable, `appVersion` set to the same SHA so it pulls `ghcr.io/nvidia/openshell/gateway:<sha>` and `:supervisor:<sha>`.
97
+
- `oci://ghcr.io/nvidia/openshell/helm-chart:0.0.0-dev.<sha>`— immutable, `appVersion` set to the same SHA so it pulls the matching `gateway`, `sandbox`, and `supervisor` images.
96
98
97
99
To smoke-test the chart for a specific dev build, dispatch `Release Dev` on the branch first, then run the kind canary steps locally pointed at the SHA-pinned chart (see "Local kind reproduction" below). The release-canary workflow itself does not currently expose `chart_version` / `image_tag` inputs.
@@ -134,7 +137,8 @@ Loopback registration auto-derives the gateway name to `openshell` if `--name` i
134
137
135
138
| Symptom | Likely cause | Where to look |
136
139
|---|---|---|
137
-
| `macos`/`ubuntu`/`fedora` job fails on `install.sh` | Latest tagged release missing an asset, checksum mismatch, or `install.sh` regression on this branch. | Job log around the `curl … install.sh \| sh` step. |
140
+
| `macos`/`ubuntu`/`fedora` job fails on `install.sh` | Dev release missing an asset, checksum mismatch, or `install.sh` regression on this branch. | Job log around the `curl … install.sh \| sh` step. |
141
+
| Sandbox create or exec fails | Published sandbox and supervisor artifacts are missing, incompatible, or cannot establish the protected runtime channel. | Gateway logs plus Docker, Podman, VM, Snap, or Kubernetes runtime diagnostics for the job. |
138
142
| `macos`/`ubuntu`/`fedora` job fails on `openshell status` | Local gateway service did not start (systemd/brew/podman). Often a driver issue. | Service logs in the job log; `OPENSHELL_COMPUTE_DRIVER` env in the "Ensure …" step. |
139
143
| `ubuntu-snap` fails after interface connection | The gateway did not recover after Docker became available, or did not become reachable within the 30-second bound. | Failure diagnostics dump Snap service/connection/change state, gateway and snapd journals, Snap logs, and port 17670 listeners. |
140
144
| `kubernetes` job fails on `helm install --wait` | Chart did not deploy in 5 min — usually image pull failure or readiness probe failing. | "Diagnostics on failure" step dumps `helm status`, manifest, pod describe, pod logs. |
0 commit comments