Skip to content

chore(deps): update LangChain Deep Agents Code to 0.1.71 - #12376

Open
nvidia-nemopatch-writer[bot] wants to merge 59 commits into
mainfrom
nemopatch/deep-agents-upgrade/f1fbd2ef6b194e8a
Open

nvidia-nemopatch-writer[bot] wants to merge 59 commits into
mainfrom
nemopatch/deep-agents-upgrade/f1fbd2ef6b194e8a

Conversation

@nvidia-nemopatch-writer

@nvidia-nemopatch-writer nvidia-nemopatch-writer Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Outcome

Upgrade managed LangChain Deep Agents Code from 0.1.55 to 0.1.71 with a hash-locked Python 3.13 dependency graph, updated startup and MCP behavior, and matching onboarding and runtime validation. Preserve the existing security, lifecycle, inference, and cleanup requirements.

Reason

Keep the managed Deep Agents release, dependency lock, startup patches, and lifecycle contract consistent with Deep Agents Code 0.1.71.

Changes

  • Adapt the Deep Agents image, managed patches, CLI entrypoint, native startup, persistent environment, and subprocess handling to the pinned release. Update the Nemotron profile and live version expectations.
  • Consolidate the fixture and gateway repairs formerly proposed in closed test(sandbox): preserve device files in double-source fixture #12611, test: make llama.cpp model replacement deterministic #12612, and fix(onboard): preserve gateway ownership and wait for all Linux threads #12614. Historical installer fixtures keep their historical executable reader; process and gateway checks retain exact ownership and bounded, redacted failure diagnostics.
  • For mixed-ownership native state on rootless Podman, complete the validated wipe as the image's pinned UID/GID 999 after the privileged pass. The provider rechecks the exact container handle; protected paths, timeout, final verification, fail-closed registry retention, and the public destroy assertion remain.
  • Bind the Deep Agents base-image, runtime validator, cleanup, and managed startup contract to one shared UID/GID JSON, resolving the migration and ownership findings in successive nine-specialist Advisor reviews.
  • Verify the native NVIDIA credential handle inside the OpenClaw sandbox before redaction, and accept that exact handle in the Hermes E2E config assertion. Preserve secret suppression and the later inference assertions. Record scoped, read-only Docker container-discovery evidence if Model Router onboarding fails.
  • Keep the v2 protected activation contract for candidate base-image builds, the v1 published-base path for older runs, and the existing assertion ratchet. The source projection, cleanup, deadline, and inference requirements are not relaxed.

Verification

Current signed, GitHub-verified commit: 6672192b5aa36c776d0ad01b17a7a627fa2f5052. This commit repairs the remaining Advisor migration finding: the managed telemetry allowlist now recognizes Deep Agents Code 0.1.71. The snapshot regression verifies the approved version in configuration and nested agent records, validates the resulting event schema, and confirms an unknown version remains other/unapproved. The regression first failed on the published parent, then all 33 focused telemetry tests passed with the fix. Lint, formatting, all 18 repository checks, and normal signed commit hooks passed. The guarded upstream SSH push passed normal publication validation and CLI typecheck. Current core CI, installer trust, security, Code Quality, and both rootless checks passed. The automatic nine-specialist Advisor reviewed exact head 6672192b against base 4e3bf44c: all nine specialists are clear, with no added or unresolved E2E recommendations, and the no-blockers gate passed. This completed review clears the repaired telemetry finding; it is not independent maintainer approval.

Current managed image qualification passed. Docker and rootless Podman each exercised all three agents for 28 turns, including native OpenClaw approval, public restarts, and external-image onboarding, identity-drift refusal, rebuild, and retention. Each recorded zero builds and all 13 registered cleanup actions passed. Both runtime artifacts and expected refusal results were inspected separately.

The new full default PR E2E run is underway for exact head 6672192b, with trusted workflow/base 4e3bf44c. It retains all default targets and jobs, Launchable opt-out, no Jetson, global mock inference, and actual NVIDIA inference for hosted catalogue profiles. It will qualify the published credential-generation readiness repair and recheck the prior runtime failures; no full-suite pass is claimed yet.

The preceding commit 74af688215ff50d05d7c543eeb2a41c61e38a5e5 passed core CI, installer trust, security, Code Quality, both rootless checks, and managed image qualification. Docker and rootless Podman each exercised all three agents for 28 turns, including native OpenClaw approval, public restarts, and external-image onboarding/rebuild/retention; both recorded zero builds and all 13 cleanup actions passed. The nine-specialist Advisor completed with eight clear specialists and one valid telemetry finding, repaired by the current commit. The completed current-head Advisor review above clears that finding. Full E2E was held for the repair and is now running; the credential-generation readiness change still needs its actual runtime result.

The results below apply to the preceding commit a26ef7851d52e967b3939d7f9e0444236d8c6a33. That commit merges canonical main 4e3bf44c57efd77cd213417c173fe60b41e2154e, including merged #12928. The shared process reader, its bounded reads, ownership checks, and matching installer fixtures now match trusted main. The upgrade's cleanup and deadline cases are retained. Main's merged OpenClaw native inference-switch repair is retained unchanged.

Local combined validation: 314 Linux tests pass across gateway identity/readiness, scoped cleanup, installer trust, and inference-switch support. CLI typecheck, reviewed runtime bundle reproducibility, lint/format, all 18 repository checks, the 1,250-direct-expect E2E assertion ratchet, semantic phase checks, and normal signed commit hooks pass. The guarded upstream SSH push also passed normal publication validation and CLI typecheck with the actual pre-push hook isolated from contributor credentials. No parser trust rule, security control, runtime deadline, assertion requirement, or exception was relaxed. The diff contains no secrets, API keys, or credentials.

Core CI passed, including all 12 CLI shards and the aggregate. The installer trust check, CodeQL, Code Quality, and both rootless validation workflows also passed.

Managed image qualification passed. Docker and rootless Podman each exercised three agents for 28 turns, including explicit native OpenClaw admin approval, public stop/start, native readiness, and external-image onboarding, drift rejection, rebuild, and retention. Each recorded zero build commands and all 13 cleanup actions passed. The first Docker attempt failed before container creation with ImagePullFailed: bytes remaining on stream; one Docker-only retry passed on the same commit and immutable digests. The original failure evidence is retained. Podman and producer jobs were retained from their successful first attempt.

The automatic nine-specialist Advisor completed on exact head a26ef785 and base 4e3bf44c: all nine specialists clear, no findings or added E2E selectors, and the no-blockers gate passed. The coordinator was a read-only shadow evaluation; this is not independent approval.

The full default PR E2E run tests exact candidate a26ef785 with trusted workflow/base 4e3bf44c. It preserves all default targets and jobs, Launchable opt-out, no Jetson, global mock inference, and actual NVIDIA inference for hosted catalogue profiles. The run completed: 70 successful jobs, 11 failed leaves, one failed aggregate, and 17 skipped jobs (99 total). These are workflow job counts, not individual test counts.

Protected AMD64 and ARM64 image builds and activation passed. Protected GPU image builds passed. All three exact candidate agent images passed GPU-backed Ollama and vLLM inference (six cases), including CUDA usability. NIM model download then failed with disk exhaustion; NIM-backed inference and the subsequent rollback phase were not reached. All six registered GPU cleanup actions passed. Deep Agents hosted onboarding, the legacy upgrade path, Model Router, and MCP OpenClaw passed. The completed failures are classified as follows:

Failed jobs Evidence and disposition
Five config-export jobs, containing seven failed tests The exporter refuses messaging metadata. The two registry failures also occur in the exact-base main run; the exporter and consuming fixtures are unchanged between base and candidate. The Hermes and local-GPU export failures have the same refusal. These are inherited export/fixture mismatches. Later assertions after the refusal remain unexecuted.
Two OpenClaw inference-switch jobs Initial onboarding, inference, and restart pass. Rebuild rejects a custom Dockerfile missing ARG NEMOCLAW_MESSAGING_PLAN_B64, before deletion or provider switching. Paired execution of the actual base and candidate fixture produces the same Dockerfile without that argument. Both failures also occur in main run38090332174, with unchanged relevant fixture and runtime source; the guard is retained.
One Hermes native-switch job The command succeeds, then the fixture expects a null endpoint although a native-to-same-native switch retains the NVIDIA endpoint. Paired execution of the unchanged base/candidate metadata function confirms the same result. Later inference assertions remain unexecuted.
One Pi native-inference job The first reply reports HTTP 401. Earlier candidate and main runs reproduced the same failure; current base/candidate generator and startup source also match. However, the current main image receipt differs, and the failed run did not capture raw generated configuration. Current-base live attribution remains unresolved; this is not conclusively excluded from qualification. No authentication retry was attempted.
One credential-generation job Candidate-owned fixture ordering: the retained child starts before the restored provider revision becomes visible. A local repair waits for the existing distinct-revision readiness condition before starting the child and preserves the equality, rotation, revocation, and cleanup assertions. The repair passes 48 focused Linux tests, the delayed-visibility red/green proof, lint/format, and 18 repository checks. The repair is now published as 74af688215ff50d05d7c543eeb2a41c61e38a5e5; normal commit and publication hooks passed. Live qualification remains pending.
One protected GPU runtime job NIM2.1.4 could not download model profile 8c91cce8… because the model cache ran out of disk space. The exact-base main GPU job failed with the same version, profile and ENOSPC error. The candidate passed all-agent Ollama/vLLM inference first; no NIM inference or rollback pass is claimed.

All registered cleanup actions passed in the eleven completed failed leaves. Runtime logs, result artifacts, and cleanup evidence were inspected. Nine failed leaves have inherited attribution supported by direct main results or paired base/candidate execution; Pi remains unresolved, and the published credential fixture repair requires live qualification. Failure attribution does not establish that later unexecuted assertions passed.

The exact-base main push run completed with 11 successful jobs, three failed leaves, one failed aggregate, and 26 skipped jobs. Its two registry failures match the candidate's messaging export refusal. Its protected GPU job failed during NIM model download with ENOSPC, established from the causal log excerpt. The completed candidate GPU job now reproduces the same NIM download failure. This main run used change-based selection and is not a matched full baseline. The older full main baseline 37469111544 remains historical evidence; subsequent main changes prevent treating it as current-base qualification.

Remaining qualification

All current CI, managed activation, and nine-specialist Advisor feedback for 6672192b is collected and clear. The full E2E run is in progress. Retain the unresolved Pi attribution, NIM/rollback evidence gaps, and later unexecuted assertions from the preceding full run until new evidence resolves them. A narrower managed-image pass does not clear the full suite. CodeRabbit remains deferred at the user's direction; its skipped check is not actual review evidence. Independent approval remains required.


Signed-off-by: Prekshi Vyas prekshiv@nvidia.com

Patch-Walker-Manifest: sha256:a0f61cff523ec0832bb6e461e1dfe730a415d48e0890f72ac51a6895d69327f0
Patch-Walker-Action: sha256:b7fb4a31d109f7d4646d6d1e67c20ffc5a2cb05b77a4b014589c518fec0733f9

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: a107102c-eab4-45b0-af61-84659b2d1ce5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 6672192 in the nemopatch/deep-agent... branch is 97%. The line coverage in commit 63002cd in the main branch is 96%.

Show a line coverage summary of the most impacted files.
File main 63002cd nemopatch/deep-agent... 6672192 +/-
nemoclaw/src/onboard/config.ts 98% 96% -2%
nemoclaw/src/index.ts 94% 93% -1%
nemoclaw/src/bl...print/runner.ts 95% 95% 0%
nemoclaw/src/bl...ime-identity.ts 97% 97% 0%
nemoclaw/src/bl...t-management.ts 100% 100% 0%
nemoclaw/src/co.../config-show.ts 100% 100% 0%
nemoclaw/src/commands/slash.ts 100% 100% 0%
nemoclaw/src/on...native-route.ts 0% 100% +100%

TypeScript / code-coverage/cli

The overall line coverage in commit 6672192 in the nemopatch/deep-agent... branch is 86%. The line coverage in commit 63002cd in the main branch is 84%.

Show a line coverage summary of the most impacted files.
File main 63002cd nemopatch/deep-agent... 6672192 +/-
src/lib/onboard.ts 62% 47% -15%
src/lib/actions...ess-recovery.ts 65% 78% +13%
src/lib/state/l...diness-lease.ts 66% 82% +16%
src/lib/inferen...ollama/proxy.ts 41% 61% +20%
src/lib/onboard.../application.ts 55% 84% +29%
src/lib/domain/...y/dimensions.ts 0% 71% +71%
src/lib/actions...ry/operation.ts 0% 76% +76%
src/lib/actions...try/snapshot.ts 0% 78% +78%
src/lib/inferen...nvidia/index.ts 0% 85% +85%
src/lib/onboard...ternal-image.ts 0% 91% +91%

Updated October 11, 2026 07:47 UTC

@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@prekshivyas
prekshivyas marked this pull request as ready for review September 29, 2026 02:25
@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@prekshivyas
prekshivyas marked this pull request as draft September 29, 2026 05:56
@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review skipped.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review skipped.

@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review skipped.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review skipped.

@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review skipped.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review skipped.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai help

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.

CodeRabbit commands

These commands are invoked using PR/Issue comments.

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai review --preview-config to test the unmerged CodeRabbit configuration on a draft PR. The requester must have repository write access; preview results are non-authoritative.
  • @coderabbitai rate limit to show your current review rate limit status.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai track in a human-authored review thread to track the original finding until CodeRabbit verifies it is fixed.
  • @coderabbitai fixed in a tracked review thread to verify the current code against the original finding.
  • @coderabbitai evaluate custom pre-merge check --instructions <custom-checks-instructions> --name <custom-checks-title> [--mode <error|warning>] to validate the custom pre-merge checks instructions. Defaults to error when --mode is omitted.
  • @coderabbitai ignore pre-merge checks to override pre-merge checks and get an approval on PR.
  • @coderabbitai run pre-merge checks to run pre-merge checks on the pull request.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai generate sequence diagram to generate a sequence diagram of the changes in this PR.
  • @coderabbitai generate unit tests to generate unit tests for this PR.
  • @coderabbitai emit path instructions to emit generated path-specific review instructions for this repository.
  • @coderabbitai generate project vocabulary to list vocabulary that is specific to this repository.
  • @coderabbitai resolve merge conflict to automatically resolve merge conflicts.
  • @coderabbitai autofix to automatically fix issues in the current review thread, or all unresolved review comments when used in the PR conversation.
  • @coderabbitai autopilot to enable Autopilot to fix CodeRabbit findings and required CI, and resolve merge conflicts.
  • @coderabbitai autopilot resume to resume Autopilot for this PR.
  • @coderabbitai autopilot stop to stop Autopilot for this PR.
  • @coderabbitai fix-ci to automatically fix failing CI checks in a stacked pull request.
  • @coderabbitai fix-ci commit to automatically fix failing CI checks by committing fixes to the current branch.
  • @coderabbitai resolve to resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai generate configuration to create a PR that adds the current resolved configuration as .coderabbit.yaml (or show it if already present).
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore or @coderabbit ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

Status, support, documentation and community

  • Visit our status page to check the current availability of CodeRabbit.
  • Create a ticket on our support page for assistance with any issues or questions.
  • Visit our documentation site for detailed information on how to use CodeRabbit.
  • Join our Discord community to connect with other users and get help from the community.
  • Follow us on X/Twitter for updates and announcements.

@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai pause

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor
✅ Action performed

Reviews paused.

@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review skipped.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai full review

prekshivyas added a commit that referenced this pull request Oct 9, 2026
…2847)

## Outcome

PR E2E uses the upgrade commit's reviewed dependency inputs instead of
forcing main's versions. This change consolidates #12848's Deep Agents
controller fix and extends candidate selection through protected CPU/GPU
image builds and the OpenShell host runtime.

The acceptance target is at most two PRs for upgrades to existing
supported dependencies: normally one upgrade PR, plus one
trust/bootstrap prerequisite when necessary. Ordinary version bumps must
not need a third workflow-fix PR.

## Reason

OpenShell #12603 needs candidate runtime qualification, and Deep Agents
#12376 needs its candidate base in the protected controller. Selecting
candidate artifacts only in ordinary jobs leaves protected consumers on
main's dependencies. Pi also needs to publish source before it can
attach the resulting qualification receipts.

## Changes

- Resolve a reviewed OpenShell release from fixed files at the candidate
commit. Run this resolver only for its selected gateway consumers.
Candidate source remains inert input to pin and operational-template
verification.
- Derive image prerequisites from the existing workflow dependency
graph. Gateway-only and native-producer selections do not wait for
unused image publication. Image consumers and full release qualification
retain their gates.
- Reuse the existing candidate image path for OpenClaw, Hermes, Deep
Agents, Pi, OpenShell and shared npm inputs. Published base reuse now
checks Dockerfiles, parser inputs, ignore rules and copied files for all
three managed agents.
- Build candidate OpenClaw, Hermes and Deep Agents bases on native CPU
runners. Export each as OCI content with its agent, source, workflow,
platform and run identity. Protected GPU consumers verify those bytes
and identities before offline use; they reject published-base
substitution for PR runs.
- Project only reviewed OpenShell modules and release literals into the
trusted GPU controller. Select the reviewed candidate SDK archive,
retain the trusted dependency graph, then build and verify the CLI.
Restore the seven projected source files after qualification. These
steps reuse existing pin, archive and dependency-resolution controls
because arbitrary candidate host code cannot run with protected
credentials.
- Reuse main's Pi `--publication` check for local source publication,
including later repairs in the same PR. The same PR then adds both
published receipts and matching authority. CI remains strict; partial
refreshes and source drift fail.
- Retain verified-byte receipt parsing, staging Launchable opt-in,
failure propagation, resource cleanup and full-release gates. Update the
owning E2E guidance.
- Refresh both Pi qualification receipts from the successful candidate
image publication. Correct the managed-base fixture's platform and
image-label inputs. Validate and read protected files through the same
descriptor, with symlink and hardlink rejection tests. Add fixed,
non-secret approval-selector failure categories without changing its
acceptance rules.

## Verification

Current commit: `da4ce1d219e538cab23cb519aa65e90fda55c8e7`; base:
`6a02aac7f0053978a20eaed73159386e0ad2aff9`.

- [Core CI](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126626)
passed, including all twelve CLI shards, coverage, static checks and the
final gate. [Security
scanning](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126621)
passed.
- [Managed-image publication and
activation](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126620)
passed. Both native Pi producers and all three managed-agent producers
succeeded. Docker and Podman artifacts bind the current commit and image
digests. Each reports 28 controlled-inference turns, zero activation
builds and 13 successful cleanup callbacks.
- [Self-hosted GPU
qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/37865127484)
passed on attempt 2. The initial selector timed out before managed
publication completed; one affected-job rerun after publication
succeeded passed selection and the live test. Verified evidence binds
`da4ce1d`, records full GPU offload, an authenticated real OpenClaw
agent turn, public runtime destruction and provider resources already
absent. All three cleanup callbacks passed.
- [Focused manual
qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/37869966568)
passed from trusted main, including Relevant E2E. All five selected jobs
passed: cloud onboarding, full OpenClaw E2E, Hermes E2E, and
OpenClaw/Hermes security posture. Verified artifacts bind the current PR
commit, workflow and dispatch correlation; each reports one passed test
with no failures, skips or errors. All recorded cleanup callbacks
passed. These tests do not establish candidate OpenShell 0.1.2 coverage.
Jetson, DGX Spark queue and staging Launchable opt-ins were false; full
Release qualification was not selected.
- Focused local validation of the expanded repair passed 13 files / 571
distinct tests. Projection tests cover immutable commits, reviewed
templates, SDK integrity, dependency metadata, tampering, filesystem
redirection, rollback and restoration. Executable SDK fixtures exercise
installation/import without lifecycle scripts or package credentials.
- Image handoff tests cover three agents and both native platforms. They
reject wrong-agent, source, workflow, run, platform and digest evidence.
Dependency-input regressions select candidate artifacts without workflow
edits and reject fallback to main after failed candidate publication.
- OpenShell #12603 package and lock inputs at
`f473315ca9b64cab56305f3bf4a15a877f0904b2` select reviewed SDK `0.1.2`
through the pure projector. This is not live SDK/runtime qualification.
- All four Pi checker/runner conflicts are resolved; those files match
the recorded main commit. The isolated checker/runner suite passed 57
tests. Normal commit hooks, isolated pre-push publication validation and
CLI TypeScript passed. All six PR commits are GitHub Verified.
- Local broad coverage could not finish under the approved macOS
isolation. The current Linux CI coverage result above supplies the
completed broad gate; no local broad-check pass or waiver is claimed.
- The diff contains no secrets, API keys or credentials.

## Review notes

Sensitive paths include `.github/workflows/e2e.yaml`, changed
`scripts/**`, `tools/e2e/**` and
`tools/pr-review-advisor/REVIEW-QUEUE.md`. Source self-review covers
candidate admission, protected execution, prerequisite propagation,
OCI/SDK verification and cleanup.

The [actual Advisor
run](https://github.com/NVIDIA/NemoClaw/actions/runs/37866718854)
reviewed current commit `da4ce1d` against base `6a02aac7`. All nine
specialists completed with no findings. Their artifacts and published
review were read. The deterministic E2E floor remains required; clear
reviews do not waive it.

[CodeRabbit's actual
review](#12847 (comment))
covers the final repair from `2cde38759` to `da4ce1d` and reports no
actionable comments. All three recorded review threads are resolved.
Earlier parity, receipt, fixture, pathname-race and diagnostic findings
were repaired; current core CI and security scanning passed afterward.

All reported PR checks and the focused manual E2E run are green on
`da4ce1d`. GitHub reports no merge conflicts, but human review remains
required. The protected qualification boundary below remains unresolved;
no automated review grants human approval or merge authority.

### Remaining qualification boundary

Current trusted main accepts only the v1 protected activation contract;
this PR introduces the v2 controller needed by candidate builds. Running
that known-rejected protected path before adoption would not qualify it.
Live protected candidate OpenShell/SDK projection therefore still needs
the adopted trusted controller, followed by testing the existing upgrade
PR. No third workflow PR should be needed for that supported path.

The completed Docker/Podman tests do not establish OpenShell 0.1.2
coverage or every dependency combination. Both current native Pi
publications and strict CI passed; Pi source publication and receipt
attachment remain within this PR. New release trust, SDK dependency
graphs, permissions or controller protocols may require the one allowed
trust/bootstrap prerequisite.

This PR does not claim full release qualification, waive missing
evidence, resolve the separate inference epic, or authorize merge.

---
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Reliability**
* E2E checks can skip managed-image publication when selected checks
don’t require those images, while still enforcing publication for
dependent checks.
* Protected runtime checks verify candidate image artifacts and use
reviewed OpenShell sources and SDK versions.
* Admin approval selection errors now produce specific diagnostics
without exposing sensitive details.
* **Compatibility**
* OpenShell gateway checks resolve the version from the selected
candidate rather than relying on a fixed version.
* **Documentation**
* Added guidance on managed-image handling, E2E prerequisites, and
protected runtime checks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Comment on lines +117 to +119
const script = livePlaceholderProbeScript()
.replace("/sandbox/.hermes/.env", fixture)
.replace('glob.glob("/proc/[0-9]*/environ")', "[]");
Comment on lines +117 to +119
const script = livePlaceholderProbeScript()
.replace("/sandbox/.hermes/.env", fixture)
.replace('glob.glob("/proc/[0-9]*/environ")', "[]");
prekshivyas added a commit that referenced this pull request Oct 11, 2026
## Outcome
Linux gateway recovery, cleanup, drift detection, and Podman readiness
share one bounded process-identity reader. A zombie leader can recover
identity from a live sibling in its own thread group, and healthy
gateways retain readiness and ownership when they inherit an environment
larger than 64 KiB. Incomplete identity still fails closed.

## Reason
The full E2E run for #12376 failed to compile its protected trusted-main
checkout because the projected candidate runtime imports this reader,
which main lacks. The reader and its production consumers must reach
main before that protected GPU/rollback/cleanup path can qualify the
upgrade. This PR keeps the protected projection allowlist unchanged.

## Changes
- Centralize gateway cmdline, environment, and executable reads while
preserving executable, user, namespace, target, supervisor/cgroup, and
repeated identity checks.
- Stream at most 64 sibling entries. Keep command/status reads capped at
64 KiB; allow environment reads up to 6 MiB to cover [Linux's documented
exec ceiling](https://man7.org/linux/man-pages/man2/execve.2.html).
Allocate 4 KiB initially and grow only as data arrives; oversized
identity is rejected without trusting a partial value.
- Exercise readiness and scoped ownership with 128 KiB and 3 MiB
inherited environments on both live leaders and live siblings. Cover
over-limit refusal and oversized-command `ps` fallback for matching and
unrelated executables.
- Align both command-reference scan descriptions with the uninstall
guide. Generated OpenClaw, Hermes, and Deep Agents Code references
retain the bounded-scan recovery wording.

## Verification
- Focused Linux tests: 221 passed across six affected files in a
credential-free container. After splitting conditional test setup into
explicit cases, all 58 tests in the two affected files passed again; the
other four files are unchanged. Zombie-leader executable recovery
coverage is retained.
- Regression reproduction against the published `4f3b672b9` reader: four
large-environment readiness cases failed, then passed with this repair.
- `npm run docs`: passed; generated reference variants inspected.
- `npm run lint`: passed, including formatting and all 18 repository
checks.
- Normal signed commit hooks and isolated normal pre-push publication
validation: passed, including CLI typecheck.
- Prior `4f3b672b9` [core
CI](https://github.com/NVIDIA/NemoClaw/actions/runs/38091842719),
[managed Docker and Podman
activation](https://github.com/NVIDIA/NemoClaw/actions/runs/38091842738),
[selected self-hosted
qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/38091844207),
[rootless Linux
E2E](https://github.com/NVIDIA/NemoClaw/actions/runs/38091842723), and
[Podman CPU
proof](https://github.com/NVIDIA/NemoClaw/actions/runs/38091842760)
passed. These results precede the latest repair and do not qualify it.
- The diff contains no secrets, API keys, or credentials.

## Review notes
Latest repair: `e597da662323692be50e2fc66035327ec4d8c93f`. It addresses
[Deepak's requested
changes](#12928 (review)),
including incremental allocation and the suggested fallback regression,
plus Advisor's remaining command-reference P1. All nine [prior Advisor
reports](https://github.com/NVIDIA/NemoClaw/actions/runs/38092989782)
were collected before this update; eight were clear and documentation
was blocked. That finding awaits a fresh exact-head review; it is not
waived.

Sensitive paths in `NVIDIA/NemoClaw` include the changed
`src/lib/onboard/**` process identity consumers. Local diff review and
the tests above cover the repair; CI, Advisor, and independent
maintainer review of the latest commit remain pending. CodeRabbit's
green paused status is not a completed review. No approval or merge is
claimed.

The separate full #12376 E2E objective remains open. No additional
manual E2E selectors were recommended by the nine specialists; the
existing lifecycle and managed-runtime validation floor remains distinct
from the passing narrower workflows. Launchable remains opted out by the
user. This change does not clear unrelated same-base E2E failures.

---
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved gateway detection and readiness checks when a process leader
has exited but another thread is still active.
* Gateway shutdown and scoped cleanup more reliably verify process
ownership before signaling, including when the leader has exited.
* When ownership cannot be confirmed, shutdown avoids signaling the
process and preserves its PID and runtime markers.
* Improved handling of missing, incomplete, or mismatched process
identity information, including during Podman readiness checks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@github-actions

Copy link
Copy Markdown
Contributor

PR Review Advisor finished for commit 6672192. Include the Advisor findings in the complete PR feedback collection. Verify and group valid findings before repair.

Request review only when Require no Advisor blockers is green.

All previous runs

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: packaging Packages, images, registries, installers, or distribution area: security Security controls, permissions, secrets, or hardening integration: dcode LangChain Deep Code integration behavior needs: unblock Blocked item needs dependency or decision resolved platform: container Affects Docker, containerd, Podman, or images platform: linux Affects non-Ubuntu Linux environments

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants