fix(openclaw): validate runtime version output#6878
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughA shared SemVer extraction helper is added to the Docker image. OpenClaw build-time version checks and gateway verification now parse structured version output, with tests covering decorated, malformed, and failed responses. ChangesOpenClaw version parsing
Estimated code review effort: 3 (Moderate) | ~20 minutes Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
PR Review Advisor — InformationalAdvisor assessment: Informational / high confidence Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: 1 optional E2E recommendation
1 warning · 0 suggestionsWarningsWarnings do not block.
|
7d35077 to
c7b0f4d
Compare
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Dockerfile`:
- Around line 301-302: Update both OpenClaw version-detection call sites around
CUR_VER and the corresponding second version variable to check the status of
openclaw --version and extract-semver explicitly. Remove the || true and
0.0.0/unknown fallbacks, and fail the Docker build immediately when either
command fails or produces an invalid/unclassified version; preserve normal
patching only for successfully parsed versions.
In `@scripts/extract-semver.sh`:
- Around line 7-9: The version extraction must target the OpenClaw version
instead of selecting the first unrelated semantic version. In
scripts/extract-semver.sh lines 7-9, restrict matching to the OpenClaw-labeled
output or otherwise make extraction target-aware; in
src/lib/verify-deployment.ts lines 210-213, pass "openclaw --version" to
parseVersionFromText.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 056219d6-b8f9-4eab-80f6-b677df01b272
📒 Files selected for processing (5)
Dockerfilescripts/extract-semver.shsrc/lib/verify-deployment.test.tssrc/lib/verify-deployment.tstest/openclaw-version-parser.test.ts
|
Addressed Advisor blocker PRA-1 in e6bed8d: the install-block harness now stages and remaps the production OpenClaw version extractor. Exact provenance reuse is exercised with decorated output, and malformed output plus command failure are both proven to stop before npm pack/install. Validation: npm exec -- vitest run test/openclaw-integrity-pin-base.test.ts test/openclaw-integrity-pin-contract.test.ts test/openclaw-integrity-pin-plugin-install.test.ts test/openclaw-version-parser.test.ts src/lib/verify-deployment.test.ts (87 passed), npm run typecheck:cli, and npm run check:diff passed. |
|
✨ Thanks for the fix. Hardening the OpenClaw version parsing to fail closed on malformed output improves deployment reliability. Ready for maintainer review. Related open issues: |
prekshivyas
left a comment
There was a problem hiding this comment.
Reviewed the version parsing and fail-closed Docker/runtime paths. The parser is deliberately label-aware, command failures are rejected, and the focused tests cover decorated, malformed, and failed output. No blocking findings.
prekshivyas
left a comment
There was a problem hiding this comment.
Re-reviewed the current head after syncing main. The parser is now included in optimized build-context staging and both Dockerfile harnesses execute the real helper; the formerly failing integration suites pass 45/45, with CLI build/typecheck and hooks green.
prekshivyas
left a comment
There was a problem hiding this comment.
Re-reviewed at d7d8da5: the TypeScript deployment verifier now mirrors the strict OpenClaw-labelled-or-bare semver grammar, including rejection of unrelated plugin versions. Focused verification tests and CLI build/typecheck pass.
|
@cv Exact-head E2E authorization is the only remaining gate for |
Signed-off-by: Ho Lim <subhoya@gmail.com>
Signed-off-by: Ho Lim <subhoya@gmail.com>
Signed-off-by: Ho Lim <subhoya@gmail.com>
d7d8da5 to
72e9853
Compare
Signed-off-by: Ho Lim <subhoya@gmail.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Ho Lim <subhoya@gmail.com>
<!-- markdownlint-disable MD041 --> ## Summary Adds the canonical pre-tag `## v0.0.95` release entry to `docs/changelog/2026-07-24.mdx`, before the existing v0.0.94 entry. The entry summarizes approved user-visible changes merged since v0.0.94 and excludes internal-only prerequisites. ## Changes - Adds the v0.0.95 summary and detailed bullets for gateway lifecycle, recovery, state transfer, inference compatibility, sandbox security, Discord policy, and E2E evidence. - Links each user-facing theme to the most specific published documentation. - Records the release entry in the shared native changelog used by the OpenClaw, Hermes, and Deep Agents guides. Source summary: - [#7246](#7246), [#7228](#7228), [#7267](#7267), [#7489](#7489), [#7509](#7509), [#7351](#7351), and [#7290](#7290) -> `docs/changelog/2026-07-24.mdx`: Gateway authority, forward teardown and retry, managed recovery, Hermes restart recovery, scoped uninstall, and orphan-aware backup behavior. - [#7344](#7344) and [#7416](#7416) -> `docs/changelog/2026-07-24.mdx`: Atomic SQLite restore and host download verification. - [#7476](#7476), [#7347](#7347), [#7281](#7281), [#7485](#7485), [#7491](#7491), and [#7422](#7422) -> `docs/changelog/2026-07-24.mdx`: Windows Ollama reuse, CDI fallback, bounded OpenRouter connection setup, Nemotron-3 request compatibility, and managed Deep Agents retry and provider-error behavior. - [#6884](#6884), [#7481](#7481), [#6878](#6878), [#7467](#7467), [#7502](#7502), [#7503](#7503), [#7504](#7504), and [#7486](#7486) -> `docs/changelog/2026-07-24.mdx`: Trusted base-image overrides, local rebuild images, runtime validation, config preservation, reviewed package updates, and fewer final-image payload layers. - [#7303](#7303) -> `docs/changelog/2026-07-24.mdx`: Scoped Discord application-command management. - [#7488](#7488), [#7465](#7465), [#7497](#7497), [#7464](#7464), [#7501](#7501), [#7494](#7494), and [#7493](#7493) -> `docs/changelog/2026-07-24.mdx`: Selected-test risk signals, retry cleanup, full root-image validation, direct-main Hermes setup, executed PR-gate evidence, nightly history, and runner wait reporting. - [#7447](#7447) is an internal pinned-runtime prerequisite and is intentionally excluded from canonical supported-integration documentation. - [#7370](#7370) adds maintainer-only advisory reconciliation tooling and does not change supported user behavior. - [#7495](#7495) updates existing documentation and does not add a new v0.0.95 behavior claim. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates the dated changelog structure, heading uniqueness, and published links. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: `docs/changelog/2026-07-24.mdx`; writing rules, documentation style, factual release meaning, and published links reviewed at exact head `58b02f2bf`. - Agent: Codex documentation writer reviewer <!-- docs-review-head-sha: 58b02f2 --> <!-- docs-review-agents-blob-sha: 9c9b36d --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: - Station profile/scenario: - Result: - Supporting evidence: ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: `npx vitest run test/changelog-docs.test.ts` passed 6 tests. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — the build passed with 0 errors and 2 Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added a new v0.0.95 changelog entry above v0.0.94. * Documented improved externally supervised gateway lifecycle ownership. * Improved snapshot restore reliability and SQLite state handling. * Tightened CLI `backup-all` behavior and host artifact verification. * Updated Windows onboarding guidance (including Ollama service reuse and CDI directory fallback). * Noted inference compatibility fixes, deeper agent failure classification, stricter base-image validation, updated Discord bot command permissions, and refined E2E release automation evidence handling. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
Summary
Replace positional
openclaw --versionparsing with validated semantic-version extraction. Decorated output now yields the actual version, while malformed output fails closed instead of influencing image upgrade and patch decisions.Related Issue
Refs #5896.
Changes
Type of Change
Quality Gates
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubnpm run check:diffpassednpx vitest run test/openclaw-version-parser.test.ts src/lib/verify-deployment.test.ts— 42 tests passednpm run build:cliandnpm run typecheck:clipasseddocker build --check -f Dockerfile .completed; six pre-existing secret-name warnings remainedbash:5.3container execution extracted decorated output and rejected a malformed four-segment valuenpm run docsbuilds without warnings (doc changes only)Signed-off-by: Ho Lim subhoya@gmail.com
Summary by CodeRabbit
openclaw --versionoutput.openclaw --versionfails or the output can’t be parsed.