Skip to content

fix(installer): fast-fail on Intel Mac before any download (#7297)#7299

Merged
senthilr-nv merged 5 commits into
mainfrom
fix/7297-macos-intel-fast-fail
Jul 23, 2026
Merged

fix(installer): fast-fail on Intel Mac before any download (#7297)#7299
senthilr-nv merged 5 commits into
mainfrom
fix/7297-macos-intel-fast-fail

Conversation

@jason-ma-nv

@jason-ma-nv jason-ma-nv commented Jul 21, 2026

Copy link
Copy Markdown
Collaborator

Summary

The public installer previously cloned NemoClaw on Intel macOS before it failed because OpenShell supports Apple Silicon only. It now rejects Intel macOS before ref resolution or network work and reports the supported architecture.

Product scope verdict: PASS. This fixes an existing public-installer defect reported in #7297 and adds no integration, recipe, image, third-party stack, or supported product surface.

Related Issue

Fixes #7297

Changes

  • Add an installer bootstrap guard that rejects Darwin on x86_64 before release-ref resolution or clone.
  • Preserve --help and --version behavior, plus installation on Apple Silicon macOS and Linux.
  • Add a focused test with distinct sentinels for ref resolution, clone, and installer execution.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification: Canonical docs already require Apple Silicon for macOS and list Intel macOS as unsupported. The change affects rejection timing and message clarity, not the support contract.
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: Automated nine-category review passed for PR SHA 48b28e5 and base SHA fe56943 with no findings: fix(installer): fast-fail on Intel Mac before any download (#7297) #7299 (comment). This does not claim human sensitive-path approval.
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: no-docs-needed
  • Evidence: docs/get-started/prerequisites.mdx already identifies Apple Silicon as the tested macOS platform, and docs/reference/platform-support.mdx lists Intel macOS as unsupported. The diff does not change the support contract or installation procedure.
  • Agent: Codex Desktop
  • PR: fix(installer): fast-fail on Intel Mac before any download (#7297) #7299

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit: not applicable
  • Station profile/scenario: not applicable
  • Result: not applicable
  • Supporting evidence: not applicable; scripts/prepare-dgx-station-host.sh is unchanged.

Verification

  • PR description includes a Signed-off-by: line and every commit appears as Verified in GitHub
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run check:diff passed when hooks were skipped or unavailable
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: npx vitest run --project integration test/install-macos-arch-guard.test.ts passed 4/4.
  • Applicable broad gate passed — npm test for broad runtime/test-harness changes; npm run check for repo-wide validation/coverage changes — command/result: Not applicable; the diff changes one installer guard and its focused test.
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, or credentials committed
  • npm run docs builds without warnings (doc changes only)
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

Signed-off-by: Jason Ma jama@nvidia.com
Signed-off-by: Senthil Ravichandran senthilr@nvidia.com

Summary by CodeRabbit

  • Bug Fixes
    • The installer now detects unsupported Intel-based Macs and stops before downloading or running installation steps.
    • Apple Silicon Macs and supported Linux systems continue through the installation process as expected.

The public curl|bash bootstrap resolved a ref and cloned the NemoClaw source
before any architecture check, so an Intel Mac (x86_64 Darwin) proceeded through
setup and only failed later when the Apple-Silicon-only OpenShell gateway binary
was unavailable — with no actionable message and after needless downloads.

Add require_supported_platform() and call it in bootstrap_main after --help/
--version handling but before ref resolution and clone. On x86_64 Darwin it
prints "Apple Silicon (aarch64) is required on macOS. Intel Mac (x86_64) is not
supported." and exits non-zero. Linux x86_64, Linux aarch64, and Apple Silicon
macOS are unaffected.

The test sources the real install.sh, stubs uname to each target platform, and
replaces the download entrypoint with a sentinel: it proves the Intel-Mac path
exits early with the message and never reaches the clone, while all supported
platforms still proceed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The installer bootstrap now rejects Intel macOS before downloading or cloning. Tests emulate supported and unsupported OS/architecture combinations and verify the corresponding bootstrap outcomes.

Changes

Platform compatibility

Layer / File(s) Summary
Add and invoke platform guard
install.sh
Adds require_supported_platform to reject macOS x86_64, and invokes it before install ref resolution and repository cloning.
Test supported and unsupported platforms
test/install-macos-arch-guard.test.ts
Stubs uname to verify Intel macOS fails before the installer entrypoint, while Apple Silicon macOS and Linux reach it.

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The PR adds an early macOS x86_64 guard and test coverage, matching the issue's fast-fail, message, and no-download requirements.
Out of Scope Changes check ✅ Passed The changes stay focused on the installer guard and its test coverage, with no obvious unrelated additions.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: the installer now fails early on Intel Macs before downloading or cloning.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/7297-macos-intel-fast-fail

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall coverage in commit 48b28e5 in the fix/7297-macos-intel... branch remains at 96%, unchanged from commit fe56943 in the main branch.

TypeScript / code-coverage/cli

The overall coverage in commit 48b28e5 in the fix/7297-macos-intel... branch remains at 80%, unchanged from commit fe56943 in the main branch.

Show a code coverage summary of the most impacted files.
File main fe56943 fix/7297-macos-intel... 48b28e5 +/-
src/lib/sandbox...rce-identity.ts 87% 87% 0%
src/lib/state/m...ock-identity.ts 95% 95% 0%
src/lib/state/m...lock-storage.ts 97% 97% 0%
src/lib/adapter...shell/client.ts 88% 90% +2%
src/lib/state/m...-acquisition.ts 84% 87% +3%

Updated July 23, 2026 18:29 UTC

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — Informational

Advisor assessment: Informational / high confidence
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions
Status: No actionable findings remain in the canonical review ledger.

Model lanes

  • GPT-5.6 Terra (primary): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Nemotron 3 Ultra (second opinion): Completed · high confidence · 0 blockers · 1 warning · 0 suggestions
  • Model comparison: normalized findings differ; normalized E2E selections differ; Nemotron reported the same number of blockers, 1 more warning, the same number of suggestions.

Nemotron output stays in workflow artifacts and does not change the assessment above.

E2E guidance

Advisory only. E2E / PR Gate selects and runs jobs independently.

Recommended E2E: cloud-onboard

1 optional E2E recommendation
  • bootstrap-install-smoke

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@test/install-macos-arch-guard.test.ts`:
- Around line 20-31: Strengthen runBootstrap so the test stubs both
resolve_release_tag and clone_nemoclaw_ref with distinct failure/sentinel
markers, alongside exec_installer_from_ref. Add assertions for Intel macOS that
none of these preflight or download markers appear, proving bootstrap_main exits
before ref resolution or cloning rather than only skipping the downstream
installer call.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: d13bbd77-1ad7-43c9-a84c-7c636e914013

📥 Commits

Reviewing files that changed from the base of the PR and between d5fa194 and 8e98a1b.

📒 Files selected for processing (2)
  • install.sh
  • test/install-macos-arch-guard.test.ts

Comment thread test/install-macos-arch-guard.test.ts
@wscurran wscurran added area: install Install, setup, prerequisites, or uninstall flow bug-fix PR fixes a bug or regression platform: macos Affects macOS, including Apple Silicon labels Jul 21, 2026
@cv cv added the v0.0.93 label Jul 22, 2026
@senthilr-nv

senthilr-nv commented Jul 23, 2026

Copy link
Copy Markdown
Collaborator

Automated security review — PR SHA 48b28e5, base SHA fe56943

Verdict: PASS. No security finding blocks independent human review. This is an automated nine-category review, not human sensitive-path approval.

Findings: None.

Category Verdict Evidence
Secrets and credentials PASS The diff adds no secret, credential, token, key, or sensitive log data.
Input validation and sanitization PASS The guard compares uname output with exact OS and architecture values. It does not evaluate or interpolate user input.
Authentication and authorization PASS The diff changes no identity, permission, endpoint, or resource-access path.
Dependencies and third-party libraries PASS The diff adds no dependency or registry change.
Error handling and logging PASS The new error identifies an unsupported platform and exposes no internal state or sensitive data.
Cryptography and data protection PASS The diff changes no cryptographic or data-protection behavior.
Configuration and security headers PASS The diff changes no container, service, port, CORS, CSP, permission, or runtime configuration.
Security testing PASS The focused test proves Intel macOS exits before ref resolution, clone, or installer execution, and proves supported platforms continue.
System security PASS The guard reduces exposure by rejecting an unsupported platform before network work. It does not weaken an existing control.

Files reviewed:

  • install.sh
  • test/install-macos-arch-guard.test.ts

@senthilr-nv senthilr-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved for head 48b28e5 against base fe56943 after all required checks and exact-pair E2E gates passed.

@senthilr-nv
senthilr-nv merged commit 7cb5ba4 into main Jul 23, 2026
104 of 107 checks passed
@senthilr-nv
senthilr-nv deleted the fix/7297-macos-intel-fast-fail branch July 23, 2026 18:51
@cv cv mentioned this pull request Jul 23, 2026
23 tasks
cv added a commit that referenced this pull request Jul 23, 2026
<!-- markdownlint-disable MD041 -->
## Summary

Adds the canonical dated `## v0.0.93` release entry to
`docs/changelog/2026-07-23.mdx`.
The entry records user-visible behavior, release validation, and
documentation controls merged after `v0.0.92`, while preserving the
pending DGX OS `7.6.x` Station Express qualification caveat.

## Changes

- Adds the parser-safe dated release entry with a summary, grouped
details, and published-route links.
- Reconciles the `v0.0.92..origin/main` commit range with merged
`v0.0.93` PRs.
- Records that no-OTA DGX OS `7.6.x` passed bounded host preflight,
while full Station Express end-to-end qualification remains pending.
- Leaves existing product pages unchanged because the source PRs already
document their supported behavior.

### Source summary

- #7285 -> `docs/changelog/2026-07-23.mdx`: Records the existing-vLLM
ownership choice and resumable Station handoff.
- #7419 -> `docs/changelog/2026-07-23.mdx`: Records bounded no-OTA DGX
OS `7.6.x` recognition and its pending end-to-end qualification.
- #7268 -> `docs/changelog/2026-07-23.mdx`: Records optional Hugging
Face authentication, output sanitization, and resumable HTTP `429`
recovery.
- #7442 -> `docs/changelog/2026-07-23.mdx`: Records clean SIGINT
handling at hidden credential prompts.
- #7299 -> `docs/changelog/2026-07-23.mdx`: Records Intel macOS
rejection before ref resolution or network work.
- #7296 -> `docs/changelog/2026-07-23.mdx`: Records the DGX Spark
non-interactive local-vLLM selection order.
- #7342 -> `docs/changelog/2026-07-23.mdx`: Records delegated protected
E2E approvals in the grouped release-validation bullet.
- #7373 -> `docs/changelog/2026-07-23.mdx`: Records base-image
publication gating before final-main fanout.
- #7388 -> `docs/changelog/2026-07-23.mdx`: Records semantic phase
runtime summaries.
- #7397 -> `docs/changelog/2026-07-23.mdx`: Records progress coverage
hardening.
- #7391 -> `docs/changelog/2026-07-23.mdx`: Records centralized
larger-runner routing.
- #7423 -> `docs/changelog/2026-07-23.mdx`: Records one retry for
confirmed hosted-runner loss.
- #7399 -> `docs/changelog/2026-07-23.mdx`: Records runner-comparison
telemetry.
- #7270 -> `docs/changelog/2026-07-23.mdx`: Records staging Brev
Launchable validation.
- #7426 -> `docs/changelog/2026-07-23.mdx`: Records filtering of
irrelevant base-image run history.
- #7333 -> `docs/changelog/2026-07-23.mdx`: Records aligned Quickstart
platform guidance.
- #7343 -> `docs/changelog/2026-07-23.mdx`: Records documentation-writer
receipt collection.
- #7400 -> `docs/changelog/2026-07-23.mdx`: Records the
documentation-writer receipt requirement for docs-only PRs.
- #7413 -> `docs/changelog/2026-07-23.mdx`: Records removal of redundant
receipt PR metadata.
- #7405 -> `docs/changelog/2026-07-23.mdx`: Records corrected inference
CLI references.
- #7389 -> `docs/changelog/2026-07-23.mdx`: Records completion of the
v0.0.91 documentation audit.

`#7384` is an internal refactor with no intended runtime behavior
change.
`#7401` updates internal CodeQL Actions dependencies.
`#7376` is already contained in `v0.0.92`, so it is outside the
release-entry scan range despite its retained planning label.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [x] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [ ] Tests added or updated for changed behavior
- [x] Existing tests cover changed behavior — justification:
`test/changelog-docs.test.ts` validates dated changelog structure, SPDX
syntax, and version headings.
- [ ] Tests not applicable — justification:
- [x] Docs updated for user-facing behavior changes
- [ ] Docs not applicable — justification:
- [ ] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [ ] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification:
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## Documentation Writer Review

- [x] Documentation writer subagent reviewed the completed changes
- Result: `docs-updated`
- Evidence: Reviewed `docs/changelog/2026-07-23.mdx` against
`WRITING.md`, `docs/CONTRIBUTING.md`, `docs/.docs-skip`,
`docs/index.yml`, the six user-visible source PRs, and the remaining
grouped release commits. The review corrected an ambiguous qualification
claim, confirmed all published routes, preserved the DGX OS `7.6.x`
caveat, and found no remaining action.
- Agent: Codex Desktop
<!-- docs-review-head-sha: ec0a866 -->
<!-- docs-review-agents-blob-sha: 9c9b36d -->

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit: Not applicable. This PR does not change
`scripts/prepare-dgx-station-host.sh`.
- Station profile/scenario: Not applicable.
- Result: Not applicable.
- Supporting evidence: Not applicable.

## Verification

- [x] PR description includes a `Signed-off-by:` line and every commit
appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or
`npm run check:diff` passed when hooks were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests
are marked not applicable above — `npx vitest run
test/changelog-docs.test.ts`: 1 file and 6 tests passed.
- [ ] Applicable broad gate passed — Not applicable to one native
changelog file.
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only) —
completed with 0 errors and 2 existing Fern warnings.
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)
— not applicable because native changelog entries use a parser-safe MDX
SPDX comment without frontmatter.

---
Signed-off-by: Carlos Villela <cvillela@nvidia.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added the v0.0.93 changelog covering onboarding and validation
improvements.
* Documented support for additional DGX Station Express workstation
releases and clearer handling of existing vLLM workloads.
* Added guidance for optional Hugging Face authentication, resumable
rate-limit recovery, and DGX Spark provider selection.
* Clarified installer behavior on Intel macOS, release validation
requirements, hosted-runner retries, documentation checks, and supported
CLI quickstart paths.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: install Install, setup, prerequisites, or uninstall flow bug-fix PR fixes a bug or regression platform: macos Affects macOS, including Apple Silicon

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[macOS][Install] installer does not fast-fail on Intel Mac (x86_64) before downloads begin

4 participants