ci(hermes): add swap for image exports#7380
Conversation
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
📝 WalkthroughWalkthroughThe workflow adds a reusable 32G swap setup before both Hermes image exports. The workflow validator now checks its presence, commands, uniqueness, and ordering, with E2E coverage and updated documentation. ChangesHermes export swap
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit 36b15e1 in the TypeScript / code-coverage/cliThe overall coverage in commit 36b15e1 in the Show a code coverage summary of the most impacted files.
Updated |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@test/e2e/README.md`:
- Around line 413-420: Update the rebuild fixture sentence to explicitly state
that it verifies a 32 GiB swap-file floor on GitHub Actions, rather than saying
it “verifies that floor.” Keep the existing trusted control-plane and
main-workflow conditions unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 6cf2fe55-c2f0-4fa8-8c03-7dc2e004c303
📒 Files selected for processing (4)
.github/workflows/sandbox-images-and-e2e.yamltest/e2e/README.mdtest/e2e/support/sandbox-images-workflow-boundary.test.tstools/e2e/sandbox-images-workflow-boundary.mts
| The two Hermes rebuild jobs and both reusable-workflow Hermes image exporters | ||
| add a bounded 32 GiB swap file on their ephemeral hosted runners before the | ||
| memory-heavy image build. The rebuild fixture verifies that floor and | ||
| provisions the same swap file on GitHub Actions when a trusted control-plane | ||
| run uses the workflow definition from `main`. Those paths build large Hermes | ||
| image layers and can otherwise exhaust the runner's default memory and swap | ||
| during Docker layer export. Other E2E jobs keep the standard runner memory | ||
| configuration. |
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
Clarify the swap-floor sentence.
“Verifies that floor” is ambiguous. Name the contract explicitly so the documentation matches the validator:
Proposed wording
-The rebuild fixture verifies that floor and provisions the same swap file
+The rebuild fixture verifies the 32 GiB swap floor and provisions the same swap file📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| The two Hermes rebuild jobs and both reusable-workflow Hermes image exporters | |
| add a bounded 32 GiB swap file on their ephemeral hosted runners before the | |
| memory-heavy image build. The rebuild fixture verifies that floor and | |
| provisions the same swap file on GitHub Actions when a trusted control-plane | |
| run uses the workflow definition from `main`. Those paths build large Hermes | |
| image layers and can otherwise exhaust the runner's default memory and swap | |
| during Docker layer export. Other E2E jobs keep the standard runner memory | |
| configuration. | |
| The two Hermes rebuild jobs and both reusable-workflow Hermes image exporters | |
| add a bounded 32 GiB swap file on their ephemeral hosted runners before the | |
| memory-heavy image build. The rebuild fixture verifies the 32 GiB swap floor and provisions the same swap file on GitHub Actions when a trusted control-plane | |
| run uses the workflow definition from `main`. Those paths build large Hermes | |
| image layers and can otherwise exhaust the runner's default memory and swap | |
| during Docker layer export. Other E2E jobs keep the standard runner memory | |
| configuration. |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@test/e2e/README.md` around lines 413 - 420, Update the rebuild fixture
sentence to explicitly state that it verifies a 32 GiB swap-file floor on GitHub
Actions, rather than saying it “verifies that floor.” Keep the existing trusted
control-plane and main-workflow conditions unchanged.
PR Review Advisor — InformationalAdvisor assessment: Informational / high confidence Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: 1 warning · 0 suggestionsWarningsWarnings do not block.
|
|
Maintainer exact-head disposition for
I accept the failed gate as a hosted-runner-loss exception for this workflow-only resource fix. I will use the maintainer exact-head admin merge after the already-running current-main platform proof reaches a terminal state, so that evidence is preserved rather than canceled. |
|
Post-merge maintainer proof on main SHA
This closes the hosted-runner-loss exception with exact post-merge main evidence; no product or sandbox-contract waiver remains for the image-build path. |
<!-- markdownlint-disable MD041 --> ## Summary Adds the canonical `## v0.0.92` release entry to `docs/changelog/2026-07-22.mdx` before the release plan is generated. The entry summarizes all ten pull requests merged after v0.0.91, including the OpenClaw security update and Jaeger runtime regression coverage. ## Changes - Added the canonical v0.0.92 changelog entry. - Recorded the user-visible, security, documentation, CI, and test changes in the release range. - #7280 -> `docs/changelog/2026-07-22.mdx`: OpenClaw 2026.7.1 and Node.js 22.23.1 security/runtime update. - #7378 -> `docs/changelog/2026-07-22.mdx`: canonical macOS watcher path validation. - #7379 -> `docs/changelog/2026-07-22.mdx`: stabilized full WSL platform validation. - #7380 -> `docs/changelog/2026-07-22.mdx`: bounded swap for hosted Hermes image exports. - #7100 -> `docs/changelog/2026-07-22.mdx`: semantic progress phases for live E2E tests. - #7376 -> `docs/changelog/2026-07-22.mdx`: restored v0.0.91 changelog history and corrected tagged guidance. - #7374 -> `docs/changelog/2026-07-22.mdx`: reviewed Homebrew formula transition for installer integrity checks. - #7346 -> `docs/changelog/2026-07-22.mdx`: provider-neutral headless server deployment guidance. - #7381 -> `docs/changelog/2026-07-22.mdx`: stabilized Hermes guard timing and WSL ownership fixtures. - #7339 -> `docs/changelog/2026-07-22.mdx`: real-artifact Jaeger header remediation regression coverage. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates the canonical dated changelog and release heading contract. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable - Station profile/scenario: Not applicable - Result: Not applicable - Supporting evidence: Not applicable ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts` passed 6/6 tests. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to a changelog-only change. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — passed with 0 errors and 2 pre-existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Carlos Villela <cvillela@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added `v0.0.92` release notes covering sandboxing updates (OpenClaw/Node.js bumps, integrity pinning remediation, mcporter handling, and upgrade validation). * Updated deployment guidance for provider-neutral headless installs, and improved live E2E test reporting plus phase-plan validation. * Tightened installer integrity-check messaging during an OpenShell Homebrew transition and expanded platform/image validation (including macOS/WSL timing) and hosted image export behavior. * Restored the previously missed `v0.0.91` changelog entry and release validation guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Summary
Why
Current main completed all 63 Hermes Dockerfile steps, then received runner shutdown during final layer export twice: attempt 1 and failed-only retry. The repository already documents and uses this 32 GiB swap mitigation for Hermes rebuild exports. This applies the same bounded mitigation to the only two reusable-workflow jobs that export Hermes images. It does not change the Dockerfile, image contents, or runtime behavior.
Verification
CI=1 npx vitest run --project e2e-support test/e2e/support/sandbox-images-workflow-boundary.test.ts test/e2e/support/hermes-secret-boundary-workflow.test.ts --reporter=verbose(15 passed)git diff --checkpassedSigned-off-by: Aaron Erickson aerickson@nvidia.com