Skip to content

ci(wsl): stabilize full platform suite#7379

Merged
ericksoa merged 2 commits into
mainfrom
codex/raise-wsl-vitest-timeout
Jul 22, 2026
Merged

ci(wsl): stabilize full platform suite#7379
ericksoa merged 2 commits into
mainfrom
codex/raise-wsl-vitest-timeout

Conversation

@ericksoa

@ericksoa ericksoa commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Summary

  • raise the Platform Vitest Main Watch WSL job limit from 60 to 90 minutes
  • capability-gate the one Docker-backed Hermes root-container contract when the platform has no Docker daemon
  • keep the concurrent latest safety test semantic across Git rejection-message variants

Why

The preserved current-main platform run 29914791092 completed 19,226 WSL tests and exposed two platform assumptions after the earlier timeout was removed:

  • the fresh WSL distro intentionally installs no Docker CLI or daemon, while one Hermes test gated only on process.platform === "linux"; Node returned immediate Docker ENOENT with status: null
  • WSL Git correctly rejected the stale compare-and-swap with incorrect old value provided instead of the older cannot lock ref prose; the remote object invariants prove latest was not overwritten

The job-level 90-minute allowance remains necessary because 29910675239 previously reached the exact 60-minute cap while the suite was still passing and progressing. Production Hermes and release behavior are unchanged.

Verification

  • focused concurrent-tag safety test passed at a 60-second budget
  • Hermes topology and platform workflow contracts: 5 passed, 2 intentional capability skips
  • Biome check passed
  • git diff --check passed

Signed-off-by: Aaron Erickson aerickson@nvidia.com

Summary by CodeRabbit

  • Chores
    • Increased the maximum runtime for the WSL test workflow from 60 to 90 minutes to reduce timeout risk during longer runs.
  • Tests
    • Improved Linux root-container integration tests to run only when the needed container runtime capability is available.
    • Made assertion failure reporting more reliable by using additional error context when available.
    • Relaxed a concurrent “latest tag” test to check failure behavior without requiring a specific error message, while still verifying the remote tag was not overwritten.

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Copilot AI review requested due to automatic review settings July 22, 2026 11:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The WSL Vitest timeout increases from 60 to 90 minutes. Docker-backed tests now require an available Linux Docker runtime, and assertions use more defensive error reporting. The concurrent tag test validates failure status and tag preservation without matching a specific error message.

Changes

CI and test maintenance

Layer / File(s) Summary
Update WSL Vitest timeout
.github/workflows/platform-vitest-main.yaml, test/platform-vitest-main-workflow.test.ts
The wsl-vitest job timeout and matching test expectation change from 60 to 90 minutes.
Gate Docker-backed runtime tests
test/hermes-runtime-config-guard-topology.test.ts
Root-container tests are skipped unless Linux Docker capability is available, and status assertions fall back to available error or output messages.
Relax concurrent tag failure assertion
test/release-latest-tag.test.ts
The concurrent update test checks non-zero failure status and verifies that the remote latest tag remains unchanged without requiring a specific lock error message.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested labels: area: ci

Suggested reviewers: copilot, apurvvkumaria

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is concise and broadly matches the WSL CI timeout and stability changes in the workflow and tests.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/raise-wsl-vitest-timeout

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall coverage in commit 2f4876b in the codex/raise-wsl-vite... branch remains at 96%, unchanged from commit 091ca29 in the main branch.

TypeScript / code-coverage/cli

The overall coverage in commit 2f4876b in the codex/raise-wsl-vite... branch remains at 80%, unchanged from commit 091ca29 in the main branch.

Show a code coverage summary of the most impacted files.
File main 091ca29 codex/raise-wsl-vite... 2f4876b +/-
src/lib/onboard...ndbox-create.ts 83% 33% -50%
src/lib/inferen...lama/process.ts 100% 50% -50%
src/lib/onboard...-create-plan.ts 88% 75% -13%
src/lib/onboard...-desktop-gpu.ts 89% 77% -12%
src/lib/onboard...ndbox-create.ts 91% 83% -8%
src/lib/inferen...er-lifecycle.ts 71% 65% -6%
src/lib/state/m...-acquisition.ts 89% 84% -5%
src/lib/sandbox...rce-identity.ts 87% 87% 0%
src/lib/shields/index.ts 71% 72% +1%
src/lib/domain/.../connect-env.ts 89% 97% +8%

Updated July 22, 2026 12:20 UTC

@github-actions

github-actions Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — Informational

Advisor assessment: Informational / high confidence
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions
Status: No actionable findings remain in the canonical review ledger.

Model lanes

  • GPT-5.6 Terra (primary): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Nemotron 3 Ultra (second opinion): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Model comparison: normalized findings match; normalized E2E selections differ; severity counts match.

Nemotron output stays in workflow artifacts and does not change the assessment above.

E2E guidance

Advisory only. E2E / PR Gate selects and runs jobs independently.

Recommended E2E: None

2 optional E2E recommendations
  • hermes-shields-config
  • full-e2e

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Copilot AI review requested due to automatic review settings July 22, 2026 12:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@ericksoa ericksoa changed the title ci(wsl): allow full platform suite to finish ci(wsl): stabilize full platform suite Jul 22, 2026
@ericksoa
ericksoa merged commit 56fa3f1 into main Jul 22, 2026
101 of 103 checks passed
@ericksoa
ericksoa deleted the codex/raise-wsl-vitest-timeout branch July 22, 2026 12:23
cv pushed a commit that referenced this pull request Jul 22, 2026
## Summary

- raise the Hermes Python guard test-harness allowance from 5 seconds to
90 seconds
- apply the shared allowance to the three runtime-config-guard helper
paths only
- correct the WSL root-only peer fixture to start from the production
mutable topology, `sandbox:sandbox 03770`
- assert sealing produces `root:sandbox 03770`, permits sandbox-group
runtime-state creation, rejects unlink of root-owned sealed config, and
restores the original ownership
- let the existing config-reclaim peer write probe traverse Vitest's
private temp root only for the duration of that probe, then restore its
exact mode
- leave production runtime behavior and non-guard command limits
unchanged

## Evidence

- main CI job 88920894839 returned `status: null` after the first guard
child exceeded its 5-second `spawnSync` limit; the runner and later
guard cases remained healthy
- four prior main runs passed the same case in about 0.3 seconds,
confirming a load-sensitive harness limit rather than a Hermes behavior
regression
- current-main Platform Vitest run 29919416442 passed the complete WSL
suite (1,642 files / 19,227 tests) and then reproduced the isolated
root-fixture failure
- historical run 29307612216 reproduced that fixture failure before the
OpenClaw upgrade and before #7379
- first exact-head WSL proof 29923652396 passed the complete WSL suite
and both corrected Hermes root contracts; it then exposed the next
root-only fixture defect
- that config-reclaim test completed production normalization and all
ownership/mode assertions; only its stepped-down write probe failed
because PR #6690 made Vitest's shared temp ancestor private
- current exact head `b7414d2f7f1bfd68028e9f43c11c1cc61033e266` includes
current `main` at `f9924949922f8e554f94aeefdd23a993a801e7b4`
- current exact-head platform proof:
https://github.com/NVIDIA/NemoClaw/actions/runs/29929199550
- focused `nemoclaw-start-perms` suite: 16 passed, 3 Linux-root
capability skips on macOS
- `npm run build:cli` and `npm run check:diff`: passed
- independent review of the narrow changes: no production findings

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>

---------

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@cv cv mentioned this pull request Jul 22, 2026
22 tasks
cv added a commit that referenced this pull request Jul 22, 2026
<!-- markdownlint-disable MD041 -->
## Summary

Adds the canonical `## v0.0.92` release entry to
`docs/changelog/2026-07-22.mdx` before the release plan is generated.
The entry summarizes all ten pull requests merged after v0.0.91,
including the OpenClaw security update and Jaeger runtime regression
coverage.

## Changes

- Added the canonical v0.0.92 changelog entry.
- Recorded the user-visible, security, documentation, CI, and test
changes in the release range.
- #7280 -> `docs/changelog/2026-07-22.mdx`: OpenClaw 2026.7.1 and
Node.js 22.23.1 security/runtime update.
- #7378 -> `docs/changelog/2026-07-22.mdx`: canonical macOS watcher path
validation.
- #7379 -> `docs/changelog/2026-07-22.mdx`: stabilized full WSL platform
validation.
- #7380 -> `docs/changelog/2026-07-22.mdx`: bounded swap for hosted
Hermes image exports.
- #7100 -> `docs/changelog/2026-07-22.mdx`: semantic progress phases for
live E2E tests.
- #7376 -> `docs/changelog/2026-07-22.mdx`: restored v0.0.91 changelog
history and corrected tagged guidance.
- #7374 -> `docs/changelog/2026-07-22.mdx`: reviewed Homebrew formula
transition for installer integrity checks.
- #7346 -> `docs/changelog/2026-07-22.mdx`: provider-neutral headless
server deployment guidance.
- #7381 -> `docs/changelog/2026-07-22.mdx`: stabilized Hermes guard
timing and WSL ownership fixtures.
- #7339 -> `docs/changelog/2026-07-22.mdx`: real-artifact Jaeger header
remediation regression coverage.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [x] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [ ] Tests added or updated for changed behavior
- [x] Existing tests cover changed behavior — justification:
`test/changelog-docs.test.ts` validates the canonical dated changelog
and release heading contract.
- [ ] Tests not applicable — justification:
- [x] Docs updated for user-facing behavior changes
- [ ] Docs not applicable — justification:
- [ ] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [ ] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification:
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit: Not applicable
- Station profile/scenario: Not applicable
- Result: Not applicable
- Supporting evidence: Not applicable

## Verification

- [x] PR description includes a `Signed-off-by:` line and every commit
appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or
`npm run check:diff` passed when hooks were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests
are marked not applicable above — `npx vitest run
test/changelog-docs.test.ts` passed 6/6 tests.
- [ ] Applicable broad gate passed — `npm test` for broad
runtime/test-harness changes; `npm run check` for repo-wide
validation/coverage changes — command/result: Not applicable to a
changelog-only change.
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only) — passed
with 0 errors and 2 pre-existing Fern warnings.
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

---
Signed-off-by: Carlos Villela <cvillela@nvidia.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added `v0.0.92` release notes covering sandboxing updates
(OpenClaw/Node.js bumps, integrity pinning remediation, mcporter
handling, and upgrade validation).
* Updated deployment guidance for provider-neutral headless installs,
and improved live E2E test reporting plus phase-plan validation.
* Tightened installer integrity-check messaging during an OpenShell
Homebrew transition and expanded platform/image validation (including
macOS/WSL timing) and hosted image export behavior.
* Restored the previously missed `v0.0.91` changelog entry and release
validation guidance.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants