…2847)
## Outcome
PR E2E uses the upgrade commit's reviewed dependency inputs instead of
forcing main's versions. This change consolidates #12848's Deep Agents
controller fix and extends candidate selection through protected CPU/GPU
image builds and the OpenShell host runtime.
The acceptance target is at most two PRs for upgrades to existing
supported dependencies: normally one upgrade PR, plus one
trust/bootstrap prerequisite when necessary. Ordinary version bumps must
not need a third workflow-fix PR.
## Reason
OpenShell #12603 needs candidate runtime qualification, and Deep Agents
#12376 needs its candidate base in the protected controller. Selecting
candidate artifacts only in ordinary jobs leaves protected consumers on
main's dependencies. Pi also needs to publish source before it can
attach the resulting qualification receipts.
## Changes
- Resolve a reviewed OpenShell release from fixed files at the candidate
commit. Run this resolver only for its selected gateway consumers.
Candidate source remains inert input to pin and operational-template
verification.
- Derive image prerequisites from the existing workflow dependency
graph. Gateway-only and native-producer selections do not wait for
unused image publication. Image consumers and full release qualification
retain their gates.
- Reuse the existing candidate image path for OpenClaw, Hermes, Deep
Agents, Pi, OpenShell and shared npm inputs. Published base reuse now
checks Dockerfiles, parser inputs, ignore rules and copied files for all
three managed agents.
- Build candidate OpenClaw, Hermes and Deep Agents bases on native CPU
runners. Export each as OCI content with its agent, source, workflow,
platform and run identity. Protected GPU consumers verify those bytes
and identities before offline use; they reject published-base
substitution for PR runs.
- Project only reviewed OpenShell modules and release literals into the
trusted GPU controller. Select the reviewed candidate SDK archive,
retain the trusted dependency graph, then build and verify the CLI.
Restore the seven projected source files after qualification. These
steps reuse existing pin, archive and dependency-resolution controls
because arbitrary candidate host code cannot run with protected
credentials.
- Reuse main's Pi `--publication` check for local source publication,
including later repairs in the same PR. The same PR then adds both
published receipts and matching authority. CI remains strict; partial
refreshes and source drift fail.
- Retain verified-byte receipt parsing, staging Launchable opt-in,
failure propagation, resource cleanup and full-release gates. Update the
owning E2E guidance.
- Refresh both Pi qualification receipts from the successful candidate
image publication. Correct the managed-base fixture's platform and
image-label inputs. Validate and read protected files through the same
descriptor, with symlink and hardlink rejection tests. Add fixed,
non-secret approval-selector failure categories without changing its
acceptance rules.
## Verification
Current commit: `da4ce1d219e538cab23cb519aa65e90fda55c8e7`; base:
`6a02aac7f0053978a20eaed73159386e0ad2aff9`.
- [Core CI](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126626)
passed, including all twelve CLI shards, coverage, static checks and the
final gate. [Security
scanning](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126621)
passed.
- [Managed-image publication and
activation](https://github.com/NVIDIA/NemoClaw/actions/runs/37865126620)
passed. Both native Pi producers and all three managed-agent producers
succeeded. Docker and Podman artifacts bind the current commit and image
digests. Each reports 28 controlled-inference turns, zero activation
builds and 13 successful cleanup callbacks.
- [Self-hosted GPU
qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/37865127484)
passed on attempt 2. The initial selector timed out before managed
publication completed; one affected-job rerun after publication
succeeded passed selection and the live test. Verified evidence binds
`da4ce1d`, records full GPU offload, an authenticated real OpenClaw
agent turn, public runtime destruction and provider resources already
absent. All three cleanup callbacks passed.
- [Focused manual
qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/37869966568)
passed from trusted main, including Relevant E2E. All five selected jobs
passed: cloud onboarding, full OpenClaw E2E, Hermes E2E, and
OpenClaw/Hermes security posture. Verified artifacts bind the current PR
commit, workflow and dispatch correlation; each reports one passed test
with no failures, skips or errors. All recorded cleanup callbacks
passed. These tests do not establish candidate OpenShell 0.1.2 coverage.
Jetson, DGX Spark queue and staging Launchable opt-ins were false; full
Release qualification was not selected.
- Focused local validation of the expanded repair passed 13 files / 571
distinct tests. Projection tests cover immutable commits, reviewed
templates, SDK integrity, dependency metadata, tampering, filesystem
redirection, rollback and restoration. Executable SDK fixtures exercise
installation/import without lifecycle scripts or package credentials.
- Image handoff tests cover three agents and both native platforms. They
reject wrong-agent, source, workflow, run, platform and digest evidence.
Dependency-input regressions select candidate artifacts without workflow
edits and reject fallback to main after failed candidate publication.
- OpenShell #12603 package and lock inputs at
`f473315ca9b64cab56305f3bf4a15a877f0904b2` select reviewed SDK `0.1.2`
through the pure projector. This is not live SDK/runtime qualification.
- All four Pi checker/runner conflicts are resolved; those files match
the recorded main commit. The isolated checker/runner suite passed 57
tests. Normal commit hooks, isolated pre-push publication validation and
CLI TypeScript passed. All six PR commits are GitHub Verified.
- Local broad coverage could not finish under the approved macOS
isolation. The current Linux CI coverage result above supplies the
completed broad gate; no local broad-check pass or waiver is claimed.
- The diff contains no secrets, API keys or credentials.
## Review notes
Sensitive paths include `.github/workflows/e2e.yaml`, changed
`scripts/**`, `tools/e2e/**` and
`tools/pr-review-advisor/REVIEW-QUEUE.md`. Source self-review covers
candidate admission, protected execution, prerequisite propagation,
OCI/SDK verification and cleanup.
The [actual Advisor
run](https://github.com/NVIDIA/NemoClaw/actions/runs/37866718854)
reviewed current commit `da4ce1d` against base `6a02aac7`. All nine
specialists completed with no findings. Their artifacts and published
review were read. The deterministic E2E floor remains required; clear
reviews do not waive it.
[CodeRabbit's actual
review](#12847 (comment))
covers the final repair from `2cde38759` to `da4ce1d` and reports no
actionable comments. All three recorded review threads are resolved.
Earlier parity, receipt, fixture, pathname-race and diagnostic findings
were repaired; current core CI and security scanning passed afterward.
All reported PR checks and the focused manual E2E run are green on
`da4ce1d`. GitHub reports no merge conflicts, but human review remains
required. The protected qualification boundary below remains unresolved;
no automated review grants human approval or merge authority.
### Remaining qualification boundary
Current trusted main accepts only the v1 protected activation contract;
this PR introduces the v2 controller needed by candidate builds. Running
that known-rejected protected path before adoption would not qualify it.
Live protected candidate OpenShell/SDK projection therefore still needs
the adopted trusted controller, followed by testing the existing upgrade
PR. No third workflow PR should be needed for that supported path.
The completed Docker/Podman tests do not establish OpenShell 0.1.2
coverage or every dependency combination. Both current native Pi
publications and strict CI passed; Pi source publication and receipt
attachment remain within this PR. New release trust, SDK dependency
graphs, permissions or controller protocols may require the one allowed
trust/bootstrap prerequisite.
This PR does not claim full release qualification, waive missing
evidence, resolve the separate inference epic, or authorize merge.
---
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Reliability**
* E2E checks can skip managed-image publication when selected checks
don’t require those images, while still enforcing publication for
dependent checks.
* Protected runtime checks verify candidate image artifacts and use
reviewed OpenShell sources and SDK versions.
* Admin approval selection errors now produce specific diagnostics
without exposing sensitive details.
* **Compatibility**
* OpenShell gateway checks resolve the version from the selected
candidate rather than relying on a fixed version.
* **Documentation**
* Added guidance on managed-image handling, E2E prerequisites, and
protected runtime checks.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Outcome
Upgrade managed LangChain Deep Agents Code from 0.1.55 to 0.1.71 with a hash-locked Python 3.13 dependency graph, updated startup and MCP behavior, and matching onboarding and runtime validation. Preserve the existing security, lifecycle, inference, and cleanup requirements.
Reason
Keep the managed Deep Agents release, dependency lock, startup patches, and lifecycle contract consistent with Deep Agents Code 0.1.71.
Changes
Verification
Current signed, GitHub-verified commit:
6672192b5aa36c776d0ad01b17a7a627fa2f5052. This commit repairs the remaining Advisor migration finding: the managed telemetry allowlist now recognizes Deep Agents Code 0.1.71. The snapshot regression verifies the approved version in configuration and nested agent records, validates the resulting event schema, and confirms an unknown version remainsother/unapproved. The regression first failed on the published parent, then all 33 focused telemetry tests passed with the fix. Lint, formatting, all 18 repository checks, and normal signed commit hooks passed. The guarded upstream SSH push passed normal publication validation and CLI typecheck. Current core CI, installer trust, security, Code Quality, and both rootless checks passed. The automatic nine-specialist Advisor reviewed exact head6672192bagainst base4e3bf44c: all nine specialists are clear, with no added or unresolved E2E recommendations, and the no-blockers gate passed. This completed review clears the repaired telemetry finding; it is not independent maintainer approval.Current managed image qualification passed. Docker and rootless Podman each exercised all three agents for 28 turns, including native OpenClaw approval, public restarts, and external-image onboarding, identity-drift refusal, rebuild, and retention. Each recorded zero builds and all 13 registered cleanup actions passed. Both runtime artifacts and expected refusal results were inspected separately.
The new full default PR E2E run is underway for exact head
6672192b, with trusted workflow/base4e3bf44c. It retains all default targets and jobs, Launchable opt-out, no Jetson, global mock inference, and actual NVIDIA inference for hosted catalogue profiles. It will qualify the published credential-generation readiness repair and recheck the prior runtime failures; no full-suite pass is claimed yet.The preceding commit
74af688215ff50d05d7c543eeb2a41c61e38a5e5passed core CI, installer trust, security, Code Quality, both rootless checks, and managed image qualification. Docker and rootless Podman each exercised all three agents for 28 turns, including native OpenClaw approval, public restarts, and external-image onboarding/rebuild/retention; both recorded zero builds and all 13 cleanup actions passed. The nine-specialist Advisor completed with eight clear specialists and one valid telemetry finding, repaired by the current commit. The completed current-head Advisor review above clears that finding. Full E2E was held for the repair and is now running; the credential-generation readiness change still needs its actual runtime result.The results below apply to the preceding commit
a26ef7851d52e967b3939d7f9e0444236d8c6a33. That commit merges canonical main4e3bf44c57efd77cd213417c173fe60b41e2154e, including merged #12928. The shared process reader, its bounded reads, ownership checks, and matching installer fixtures now match trusted main. The upgrade's cleanup and deadline cases are retained. Main's merged OpenClaw native inference-switch repair is retained unchanged.Local combined validation: 314 Linux tests pass across gateway identity/readiness, scoped cleanup, installer trust, and inference-switch support. CLI typecheck, reviewed runtime bundle reproducibility, lint/format, all 18 repository checks, the 1,250-direct-expect E2E assertion ratchet, semantic phase checks, and normal signed commit hooks pass. The guarded upstream SSH push also passed normal publication validation and CLI typecheck with the actual pre-push hook isolated from contributor credentials. No parser trust rule, security control, runtime deadline, assertion requirement, or exception was relaxed. The diff contains no secrets, API keys, or credentials.
Core CI passed, including all 12 CLI shards and the aggregate. The installer trust check, CodeQL, Code Quality, and both rootless validation workflows also passed.
Managed image qualification passed. Docker and rootless Podman each exercised three agents for 28 turns, including explicit native OpenClaw admin approval, public stop/start, native readiness, and external-image onboarding, drift rejection, rebuild, and retention. Each recorded zero build commands and all 13 cleanup actions passed. The first Docker attempt failed before container creation with
ImagePullFailed: bytes remaining on stream; one Docker-only retry passed on the same commit and immutable digests. The original failure evidence is retained. Podman and producer jobs were retained from their successful first attempt.The automatic nine-specialist Advisor completed on exact head
a26ef785and base4e3bf44c: all nine specialists clear, no findings or added E2E selectors, and the no-blockers gate passed. The coordinator was a read-only shadow evaluation; this is not independent approval.The full default PR E2E run tests exact candidate
a26ef785with trusted workflow/base4e3bf44c. It preserves all default targets and jobs, Launchable opt-out, no Jetson, global mock inference, and actual NVIDIA inference for hosted catalogue profiles. The run completed: 70 successful jobs, 11 failed leaves, one failed aggregate, and 17 skipped jobs (99 total). These are workflow job counts, not individual test counts.Protected AMD64 and ARM64 image builds and activation passed. Protected GPU image builds passed. All three exact candidate agent images passed GPU-backed Ollama and vLLM inference (six cases), including CUDA usability. NIM model download then failed with disk exhaustion; NIM-backed inference and the subsequent rollback phase were not reached. All six registered GPU cleanup actions passed. Deep Agents hosted onboarding, the legacy upgrade path, Model Router, and MCP OpenClaw passed. The completed failures are classified as follows:
ARG NEMOCLAW_MESSAGING_PLAN_B64, before deletion or provider switching. Paired execution of the actual base and candidate fixture produces the same Dockerfile without that argument. Both failures also occur in main run38090332174, with unchanged relevant fixture and runtime source; the guard is retained.74af688215ff50d05d7c543eeb2a41c61e38a5e5; normal commit and publication hooks passed. Live qualification remains pending.8c91cce8…because the model cache ran out of disk space. The exact-base main GPU job failed with the same version, profile andENOSPCerror. The candidate passed all-agent Ollama/vLLM inference first; no NIM inference or rollback pass is claimed.All registered cleanup actions passed in the eleven completed failed leaves. Runtime logs, result artifacts, and cleanup evidence were inspected. Nine failed leaves have inherited attribution supported by direct main results or paired base/candidate execution; Pi remains unresolved, and the published credential fixture repair requires live qualification. Failure attribution does not establish that later unexecuted assertions passed.
The exact-base main push run completed with 11 successful jobs, three failed leaves, one failed aggregate, and 26 skipped jobs. Its two registry failures match the candidate's messaging export refusal. Its protected GPU job failed during NIM model download with
ENOSPC, established from the causal log excerpt. The completed candidate GPU job now reproduces the same NIM download failure. This main run used change-based selection and is not a matched full baseline. The older full main baseline 37469111544 remains historical evidence; subsequent main changes prevent treating it as current-base qualification.Remaining qualification
All current CI, managed activation, and nine-specialist Advisor feedback for
6672192bis collected and clear. The full E2E run is in progress. Retain the unresolved Pi attribution, NIM/rollback evidence gaps, and later unexecuted assertions from the preceding full run until new evidence resolves them. A narrower managed-image pass does not clear the full suite. CodeRabbit remains deferred at the user's direction; its skipped check is not actual review evidence. Independent approval remains required.Signed-off-by: Prekshi Vyas prekshiv@nvidia.com