ci(wsl): stabilize full platform suite#7379
Conversation
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
📝 WalkthroughWalkthroughThe WSL Vitest timeout increases from 60 to 90 minutes. Docker-backed tests now require an available Linux Docker runtime, and assertions use more defensive error reporting. The concurrent tag test validates failure status and tag preservation without matching a specific error message. ChangesCI and test maintenance
Estimated code review effort: 2 (Simple) | ~10 minutes Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit 2f4876b in the TypeScript / code-coverage/cliThe overall coverage in commit 2f4876b in the Show a code coverage summary of the most impacted files.
Updated |
PR Review Advisor — InformationalAdvisor assessment: Informational / high confidence Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: None 2 optional E2E recommendations
This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
## Summary - raise the Hermes Python guard test-harness allowance from 5 seconds to 90 seconds - apply the shared allowance to the three runtime-config-guard helper paths only - correct the WSL root-only peer fixture to start from the production mutable topology, `sandbox:sandbox 03770` - assert sealing produces `root:sandbox 03770`, permits sandbox-group runtime-state creation, rejects unlink of root-owned sealed config, and restores the original ownership - let the existing config-reclaim peer write probe traverse Vitest's private temp root only for the duration of that probe, then restore its exact mode - leave production runtime behavior and non-guard command limits unchanged ## Evidence - main CI job 88920894839 returned `status: null` after the first guard child exceeded its 5-second `spawnSync` limit; the runner and later guard cases remained healthy - four prior main runs passed the same case in about 0.3 seconds, confirming a load-sensitive harness limit rather than a Hermes behavior regression - current-main Platform Vitest run 29919416442 passed the complete WSL suite (1,642 files / 19,227 tests) and then reproduced the isolated root-fixture failure - historical run 29307612216 reproduced that fixture failure before the OpenClaw upgrade and before #7379 - first exact-head WSL proof 29923652396 passed the complete WSL suite and both corrected Hermes root contracts; it then exposed the next root-only fixture defect - that config-reclaim test completed production normalization and all ownership/mode assertions; only its stepped-down write probe failed because PR #6690 made Vitest's shared temp ancestor private - current exact head `b7414d2f7f1bfd68028e9f43c11c1cc61033e266` includes current `main` at `f9924949922f8e554f94aeefdd23a993a801e7b4` - current exact-head platform proof: https://github.com/NVIDIA/NemoClaw/actions/runs/29929199550 - focused `nemoclaw-start-perms` suite: 16 passed, 3 Linux-root capability skips on macOS - `npm run build:cli` and `npm run check:diff`: passed - independent review of the narrow changes: no production findings Signed-off-by: Aaron Erickson <aerickson@nvidia.com> --------- Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary Adds the canonical `## v0.0.92` release entry to `docs/changelog/2026-07-22.mdx` before the release plan is generated. The entry summarizes all ten pull requests merged after v0.0.91, including the OpenClaw security update and Jaeger runtime regression coverage. ## Changes - Added the canonical v0.0.92 changelog entry. - Recorded the user-visible, security, documentation, CI, and test changes in the release range. - #7280 -> `docs/changelog/2026-07-22.mdx`: OpenClaw 2026.7.1 and Node.js 22.23.1 security/runtime update. - #7378 -> `docs/changelog/2026-07-22.mdx`: canonical macOS watcher path validation. - #7379 -> `docs/changelog/2026-07-22.mdx`: stabilized full WSL platform validation. - #7380 -> `docs/changelog/2026-07-22.mdx`: bounded swap for hosted Hermes image exports. - #7100 -> `docs/changelog/2026-07-22.mdx`: semantic progress phases for live E2E tests. - #7376 -> `docs/changelog/2026-07-22.mdx`: restored v0.0.91 changelog history and corrected tagged guidance. - #7374 -> `docs/changelog/2026-07-22.mdx`: reviewed Homebrew formula transition for installer integrity checks. - #7346 -> `docs/changelog/2026-07-22.mdx`: provider-neutral headless server deployment guidance. - #7381 -> `docs/changelog/2026-07-22.mdx`: stabilized Hermes guard timing and WSL ownership fixtures. - #7339 -> `docs/changelog/2026-07-22.mdx`: real-artifact Jaeger header remediation regression coverage. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates the canonical dated changelog and release heading contract. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable - Station profile/scenario: Not applicable - Result: Not applicable - Supporting evidence: Not applicable ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts` passed 6/6 tests. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to a changelog-only change. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — passed with 0 errors and 2 pre-existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Carlos Villela <cvillela@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added `v0.0.92` release notes covering sandboxing updates (OpenClaw/Node.js bumps, integrity pinning remediation, mcporter handling, and upgrade validation). * Updated deployment guidance for provider-neutral headless installs, and improved live E2E test reporting plus phase-plan validation. * Tightened installer integrity-check messaging during an OpenShell Homebrew transition and expanded platform/image validation (including macOS/WSL timing) and hosted image export behavior. * Restored the previously missed `v0.0.91` changelog entry and release validation guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Summary
latestsafety test semantic across Git rejection-message variantsWhy
The preserved current-main platform run 29914791092 completed 19,226 WSL tests and exposed two platform assumptions after the earlier timeout was removed:
process.platform === "linux"; Node returned immediate DockerENOENTwithstatus: nullincorrect old value providedinstead of the oldercannot lock refprose; the remote object invariants provelatestwas not overwrittenThe job-level 90-minute allowance remains necessary because 29910675239 previously reached the exact 60-minute cap while the suite was still passing and progressing. Production Hermes and release behavior are unchanged.
Verification
git diff --checkpassedSigned-off-by: Aaron Erickson aerickson@nvidia.com
Summary by CodeRabbit