fix(installer): fast-fail on Intel Mac before any download (#7297)#7299
Conversation
The public curl|bash bootstrap resolved a ref and cloned the NemoClaw source before any architecture check, so an Intel Mac (x86_64 Darwin) proceeded through setup and only failed later when the Apple-Silicon-only OpenShell gateway binary was unavailable — with no actionable message and after needless downloads. Add require_supported_platform() and call it in bootstrap_main after --help/ --version handling but before ref resolution and clone. On x86_64 Darwin it prints "Apple Silicon (aarch64) is required on macOS. Intel Mac (x86_64) is not supported." and exits non-zero. Linux x86_64, Linux aarch64, and Apple Silicon macOS are unaffected. The test sources the real install.sh, stubs uname to each target platform, and replaces the download entrypoint with a sentinel: it proves the Intel-Mac path exits early with the message and never reaches the clone, while all supported platforms still proceed. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
📝 WalkthroughWalkthroughThe installer bootstrap now rejects Intel macOS before downloading or cloning. Tests emulate supported and unsupported OS/architecture combinations and verify the corresponding bootstrap outcomes. ChangesPlatform compatibility
Estimated code review effort: 2 (Simple) | ~10 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit 48b28e5 in the TypeScript / code-coverage/cliThe overall coverage in commit 48b28e5 in the Show a code coverage summary of the most impacted files.
Updated |
PR Review Advisor — InformationalAdvisor assessment: Informational / high confidence Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: 1 optional E2E recommendation
This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@test/install-macos-arch-guard.test.ts`:
- Around line 20-31: Strengthen runBootstrap so the test stubs both
resolve_release_tag and clone_nemoclaw_ref with distinct failure/sentinel
markers, alongside exec_installer_from_ref. Add assertions for Intel macOS that
none of these preflight or download markers appear, proving bootstrap_main exits
before ref resolution or cloning rather than only skipping the downstream
installer call.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: d13bbd77-1ad7-43c9-a84c-7c636e914013
📒 Files selected for processing (2)
install.shtest/install-macos-arch-guard.test.ts
Automated security review — PR SHA
|
| Category | Verdict | Evidence |
|---|---|---|
| Secrets and credentials | PASS | The diff adds no secret, credential, token, key, or sensitive log data. |
| Input validation and sanitization | PASS | The guard compares uname output with exact OS and architecture values. It does not evaluate or interpolate user input. |
| Authentication and authorization | PASS | The diff changes no identity, permission, endpoint, or resource-access path. |
| Dependencies and third-party libraries | PASS | The diff adds no dependency or registry change. |
| Error handling and logging | PASS | The new error identifies an unsupported platform and exposes no internal state or sensitive data. |
| Cryptography and data protection | PASS | The diff changes no cryptographic or data-protection behavior. |
| Configuration and security headers | PASS | The diff changes no container, service, port, CORS, CSP, permission, or runtime configuration. |
| Security testing | PASS | The focused test proves Intel macOS exits before ref resolution, clone, or installer execution, and proves supported platforms continue. |
| System security | PASS | The guard reduces exposure by rejecting an unsupported platform before network work. It does not weaken an existing control. |
Files reviewed:
install.shtest/install-macos-arch-guard.test.ts
<!-- markdownlint-disable MD041 --> ## Summary Adds the canonical dated `## v0.0.93` release entry to `docs/changelog/2026-07-23.mdx`. The entry records user-visible behavior, release validation, and documentation controls merged after `v0.0.92`, while preserving the pending DGX OS `7.6.x` Station Express qualification caveat. ## Changes - Adds the parser-safe dated release entry with a summary, grouped details, and published-route links. - Reconciles the `v0.0.92..origin/main` commit range with merged `v0.0.93` PRs. - Records that no-OTA DGX OS `7.6.x` passed bounded host preflight, while full Station Express end-to-end qualification remains pending. - Leaves existing product pages unchanged because the source PRs already document their supported behavior. ### Source summary - #7285 -> `docs/changelog/2026-07-23.mdx`: Records the existing-vLLM ownership choice and resumable Station handoff. - #7419 -> `docs/changelog/2026-07-23.mdx`: Records bounded no-OTA DGX OS `7.6.x` recognition and its pending end-to-end qualification. - #7268 -> `docs/changelog/2026-07-23.mdx`: Records optional Hugging Face authentication, output sanitization, and resumable HTTP `429` recovery. - #7442 -> `docs/changelog/2026-07-23.mdx`: Records clean SIGINT handling at hidden credential prompts. - #7299 -> `docs/changelog/2026-07-23.mdx`: Records Intel macOS rejection before ref resolution or network work. - #7296 -> `docs/changelog/2026-07-23.mdx`: Records the DGX Spark non-interactive local-vLLM selection order. - #7342 -> `docs/changelog/2026-07-23.mdx`: Records delegated protected E2E approvals in the grouped release-validation bullet. - #7373 -> `docs/changelog/2026-07-23.mdx`: Records base-image publication gating before final-main fanout. - #7388 -> `docs/changelog/2026-07-23.mdx`: Records semantic phase runtime summaries. - #7397 -> `docs/changelog/2026-07-23.mdx`: Records progress coverage hardening. - #7391 -> `docs/changelog/2026-07-23.mdx`: Records centralized larger-runner routing. - #7423 -> `docs/changelog/2026-07-23.mdx`: Records one retry for confirmed hosted-runner loss. - #7399 -> `docs/changelog/2026-07-23.mdx`: Records runner-comparison telemetry. - #7270 -> `docs/changelog/2026-07-23.mdx`: Records staging Brev Launchable validation. - #7426 -> `docs/changelog/2026-07-23.mdx`: Records filtering of irrelevant base-image run history. - #7333 -> `docs/changelog/2026-07-23.mdx`: Records aligned Quickstart platform guidance. - #7343 -> `docs/changelog/2026-07-23.mdx`: Records documentation-writer receipt collection. - #7400 -> `docs/changelog/2026-07-23.mdx`: Records the documentation-writer receipt requirement for docs-only PRs. - #7413 -> `docs/changelog/2026-07-23.mdx`: Records removal of redundant receipt PR metadata. - #7405 -> `docs/changelog/2026-07-23.mdx`: Records corrected inference CLI references. - #7389 -> `docs/changelog/2026-07-23.mdx`: Records completion of the v0.0.91 documentation audit. `#7384` is an internal refactor with no intended runtime behavior change. `#7401` updates internal CodeQL Actions dependencies. `#7376` is already contained in `v0.0.92`, so it is outside the release-entry scan range despite its retained planning label. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates dated changelog structure, SPDX syntax, and version headings. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: Reviewed `docs/changelog/2026-07-23.mdx` against `WRITING.md`, `docs/CONTRIBUTING.md`, `docs/.docs-skip`, `docs/index.yml`, the six user-visible source PRs, and the remaining grouped release commits. The review corrected an ambiguous qualification claim, confirmed all published routes, preserved the DGX OS `7.6.x` caveat, and found no remaining action. - Agent: Codex Desktop <!-- docs-review-head-sha: ec0a866 --> <!-- docs-review-agents-blob-sha: 9c9b36d --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable. This PR does not change `scripts/prepare-dgx-station-host.sh`. - Station profile/scenario: Not applicable. - Result: Not applicable. - Supporting evidence: Not applicable. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts`: 1 file and 6 tests passed. - [ ] Applicable broad gate passed — Not applicable to one native changelog file. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — completed with 0 errors and 2 existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — not applicable because native changelog entries use a parser-safe MDX SPDX comment without frontmatter. --- Signed-off-by: Carlos Villela <cvillela@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added the v0.0.93 changelog covering onboarding and validation improvements. * Documented support for additional DGX Station Express workstation releases and clearer handling of existing vLLM workloads. * Added guidance for optional Hugging Face authentication, resumable rate-limit recovery, and DGX Spark provider selection. * Clarified installer behavior on Intel macOS, release validation requirements, hosted-runner retries, documentation checks, and supported CLI quickstart paths. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Summary
The public installer previously cloned NemoClaw on Intel macOS before it failed because OpenShell supports Apple Silicon only. It now rejects Intel macOS before ref resolution or network work and reports the supported architecture.
Product scope verdict: PASS. This fixes an existing public-installer defect reported in #7297 and adds no integration, recipe, image, third-party stack, or supported product surface.
Related Issue
Fixes #7297
Changes
Darwinonx86_64before release-ref resolution or clone.--helpand--versionbehavior, plus installation on Apple Silicon macOS and Linux.Type of Change
Quality Gates
48b28e5and base SHAfe56943with no findings: fix(installer): fast-fail on Intel Mac before any download (#7297) #7299 (comment). This does not claim human sensitive-path approval.Documentation Writer Review
no-docs-neededdocs/get-started/prerequisites.mdxalready identifies Apple Silicon as the tested macOS platform, anddocs/reference/platform-support.mdxlists Intel macOS as unsupported. The diff does not change the support contract or installation procedure.DGX Station Hardware Evidence
scripts/prepare-dgx-station-host.shis unchanged.Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run check:diffpassed when hooks were skipped or unavailablenpx vitest run --project integration test/install-macos-arch-guard.test.tspassed 4/4.npm testfor broad runtime/test-harness changes;npm run checkfor repo-wide validation/coverage changes — command/result: Not applicable; the diff changes one installer guard and its focused test.npm run docsbuilds without warnings (doc changes only)Signed-off-by: Jason Ma jama@nvidia.com
Signed-off-by: Senthil Ravichandran senthilr@nvidia.com
Summary by CodeRabbit