fix(ci): trust exact-head Hermes swap setup#7444
Conversation
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughThe PR moves Hermes E2E swap provisioning from live Vitest execution into trusted workflow steps, adds strict workflow and helper-source validation, updates protected jobs and documentation, and adds cleanup, drift, and watch-trigger tests. ChangesTrusted Hermes E2E swap
Estimated code review effort: 4 (Complex) | ~60 minutes Sequence Diagram(s)sequenceDiagram
participant WorkflowDispatch
participant TrustedHermesSwap
participant Checkout
participant HermesE2ETests
WorkflowDispatch->>TrustedHermesSwap: validate provenance and runner
TrustedHermesSwap->>TrustedHermesSwap: provision and activate swap
TrustedHermesSwap->>Checkout: allow checkout after successful setup
Checkout->>HermesE2ETests: run Hermes E2E jobs
Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit 763fc6a in the TypeScript / code-coverage/cliThe overall coverage in commit 763fc6a in the Show a code coverage summary of the most impacted files.
Updated |
PR Review Advisor — InformationalAdvisor assessment: Informational / medium confidence Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: 2 optional E2E recommendations
This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
|
Addressed PRA-1 in 5874616. The executable fake-command harness now supplies exactly 32 GiB of existing active swap, verifies a successful exit, and pins the command log to the read-only /mnt ownership check plus active-capacity query—so no mkdir, mktemp, fallocate, mkswap, activation, swapoff, or cleanup command can run. The focused file passes all 10 tests. |
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
|
@coderabbitai review |
✅ Action performedReview finished.
|
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
|
Final exact-head status for
No actionable review threads remain. The branch is clean and the head is GitHub Verified. The formal E2E coordination check remains red because of the hosted-runner cancellation/retry-control-plane failure, so this comment records evidence rather than claiming the gate passed. |
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
prekshivyas
left a comment
There was a problem hiding this comment.
Security and correctness review of exact head d347bc2: PASS across secrets, input validation, authorization, dependencies, logging, data protection, workflow configuration, security tests, and system/TOCTOU controls. The privileged swap program is fixed in the trusted main workflow before candidate checkout, bound to the exact dispatch/workflow SHA and ephemeral GitHub-hosted Linux x64 runner, uses root-owned randomized paths with capacity bounds, and fails closed without deleting active swap on uncertain cleanup. Focused workflow-boundary and harness tests pass locally; no unresolved review threads or actionable automated findings. Merge remains gated on the refreshed exact-head CI/E2E result.
|
Maintainer CI waiver for exact head I accept the pending/non-success This waiver does not waive downstream live validation. After merge, the affected hosted Hermes E2E will be run from the trusted |
|
Downstream exact-head evidence from #7447 confirms this dependency is active. Child run 30055699724 exercised two fresh hosted-runner attempts for head |
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
prekshivyas
left a comment
There was a problem hiding this comment.
Exact-head review complete for e9691df. The staged rollout keeps the new trusted pre-checkout boundary, retains the existing exact-head helper only until the trusted workflow reaches main, and corrects the allocation to 32 GiB + 4,096 bytes so at least 32 GiB remains usable. Focused boundary/helper/workflow tests, CLI build/typecheck, source-shape, project membership, docs validation, hooks, DCO, and commit verification pass. No code or security blocker found; final approval remains contingent on refreshed CI and exact-base E2E.
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
prekshivyas
left a comment
There was a problem hiding this comment.
Exact-head review complete for 780d772. The live failure showed delayed swapon --show visibility after successful activation. Both the temporary compatibility helper and final trusted workflow now make five bounded one-second observations, require the exact swap name and capacity, never reactivate, and treat successful activation as potentially active during fail-closed cleanup. Regression suites pass 52/52, 11/11, and 42/42; typecheck, source-shape, project membership, docs, DCO, hooks, and commit verification pass. No code or security blocker found; merge remains contingent on refreshed CI and exact-base E2E.
|
Exact-head hosted result for
The new bounded observation path executed.
The job stopped before Vitest, so no Hermes product assertion ran or failed. This result does not support a short read-after-activation timing race on the current The repository variable |
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
prekshivyas
left a comment
There was a problem hiding this comment.
Re-reviewed exact head 763fc6a. The util-linux failure was caused by unsupported swapon --output syntax being parsed as --output-all. This head uses the supported --show=NAME/--show=SIZE forms in both rollout paths, and the tightened harnesses reject the old syntax. Focused tests pass (52 + 11 + 42), with type-check, repository guards, and docs validation green. Independent maintainer review remains requested because I pushed the fix.
<!-- markdownlint-disable MD041 --> ## Summary This PR adds the canonical dated release entry for NemoClaw v0.0.94 before the tag is cut. The entry reconciles all 26 commits since v0.0.93 and links each user-visible change to its owning documentation. ## Changes - Add `docs/changelog/2026-07-24.mdx` with the exact `## v0.0.94` heading, parser-safe SPDX comment, release summary, and detailed bullets. - Record sandbox restore and update behavior, onboarding and inference changes, network policy behavior, security evidence, Hermes build performance, DGX Station guidance, and E2E validation changes. - Preserve `docs/` as the source of truth without changing the AI-agent documentation routing skill. - Use [E2E run 30075443016](https://github.com/NVIDIA/NemoClaw/actions/runs/30075443016) for release QA evidence at exact tested SHA `04e6dfa883071dda9df429c66e73168e1a995cba`. ### Source summary - [#7461](#7461) -> `docs/changelog/2026-07-24.mdx`: Record the ownership-preserving Hermes image layer reduction and hosted timing comparison. - [#7460](#7460) -> `docs/changelog/2026-07-24.mdx`: Record removal of candidate Hermes swap setup from E2E validation. - [#7458](#7458) -> `docs/security/fern-5.80.1-dependency-review.md`, `docs/changelog/2026-07-24.mdx`: Record the reviewed Fern CLI update. - [#7457](#7457) -> `docs/changelog/2026-07-24.mdx`: Record periodic runner-pressure telemetry. - [#7455](#7455) -> `docs/changelog/2026-07-24.mdx`: Record non-blocking absent Fern previews. - [#7450](#7450) -> `docs/changelog/2026-07-24.mdx`: Record stable cancellation handling for live-test child processes. - [#7449](#7449) -> `docs/changelog/2026-07-24.mdx`: Record parallel plugin EXDEV coverage. - [#7448](#7448) -> `docs/changelog/2026-07-24.mdx`: Record isolated long-running E2E lanes. - [#7444](#7444) -> `docs/changelog/2026-07-24.mdx`: Record exact-head Hermes swap validation. - [#7437](#7437) -> `docs/manage-sandboxes/backup-restore.mdx`, `docs/changelog/2026-07-24.mdx`: Record gateway pairing and authenticated verification after cross-sandbox restore. - [#7436](#7436) -> `docs/manage-sandboxes/backup-restore.mdx`, `docs/reference/commands.mdx`, `docs/changelog/2026-07-24.mdx`: Record selected stale-state cleanup and Hermes virtual-environment access repair. - [#7385](#7385) -> `docs/network-policy/customize-network-policy.mdx`, `docs/changelog/2026-07-24.mdx`: Record the read-only agent-variant route check. - [#7371](#7371) -> `docs/changelog/2026-07-24.mdx`: Record host-artifact verification for session exports. - [#7359](#7359) -> `docs/changelog/2026-07-24.mdx`: Record platform validation for managed vLLM model overrides. - [#7356](#7356) -> `docs/changelog/2026-07-24.mdx`: Record token-shaped value redaction for `sandbox doctor --json`. - [#7354](#7354) -> `docs/security/advisory-early-warning.md`, `docs/changelog/2026-07-24.mdx`: Record advisory correlation and retained audit provenance. - [#7352](#7352) -> `docs/network-policy/customize-network-policy.mdx`, `docs/network-policy/integration-policy-examples.mdx`, `docs/reference/commands.mdx`, `docs/changelog/2026-07-24.mdx`: Record preset reapplication and bounded `tls: skip` guidance. - [#7345](#7345) -> `docs/security/openclaw-2026.6.10-dependency-review.md`, `docs/security/openclaw-2026.7.1-dependency-review.md`, `docs/changelog/2026-07-24.mdx`: Record reviewed npm audit exception enforcement. - [#7340](#7340) -> `docs/network-policy/customize-network-policy.mdx`, `docs/changelog/2026-07-24.mdx`: Record the repaired CLI-reference route. - [#7334](#7334) -> `docs/get-started/dgx-station-preparation.mdx`, `docs/changelog/2026-07-24.mdx`: Record the qualified OTA metadata fallback and narrowed override wording. - [#7322](#7322) -> `docs/changelog/2026-07-24.mdx`: Reconcile the gateway source tag added to plugin registration banners. - [#7284](#7284) -> `docs/manage-sandboxes/update-sandboxes.mdx`, `docs/changelog/2026-07-24.mdx`: Record read-only `upgrade-sandboxes --check` behavior and recorded-gateway selection. - [#7277](#7277) -> `docs/changelog/2026-07-24.mdx`: Reconcile deterministic gateway TCP refusal coverage. - [#7234](#7234) -> `docs/reference/troubleshooting.mdx`, `docs/changelog/2026-07-24.mdx`: Record preserved DGX Spark managed vLLM Express intent on resume. - [#7185](#7185) -> `docs/reference/troubleshooting.mdx`, `docs/changelog/2026-07-24.mdx`: Record IPv4 fallback DNS selection and exact resolver probing. - [#6820](#6820) -> `docs/reference/commands.mdx`, `docs/changelog/2026-07-24.mdx`: Record the versioned, redacted `--events=jsonl` onboarding stream. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `npx vitest run test/changelog-docs.test.ts` passed 6/6 tests. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: `docs/changelog/2026-07-24.mdx`; the writing rules, documentation style, exact release range, skip terms, published routes, and product scope were reviewed; the changelog test passed 6/6; `npm run docs` passed with route checking OK, zero errors, and two existing warnings. - Agent: Codex Desktop <!-- docs-review-head-sha: 65368f9 --> <!-- docs-review-agents-blob-sha: 9c9b36d --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable - Station profile/scenario: Not applicable - Result: Not applicable - Supporting evidence: Not applicable. This PR does not change `scripts/prepare-dgx-station-host.sh`. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts` passed 6/6 tests. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to the dated changelog entry. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only). The build passed with zero errors and two existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only). Native dated changelog entries use the required parser-safe MDX SPDX comment and no frontmatter. --- Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added the v0.0.94 release changelog. * Documented improvements to sandbox snapshot and restore behavior. * Added updates for gateway selection, policy comparisons, onboarding event output, and DGX recovery workflows. * Documented enhanced diagnostics redaction, npm audit provenance, image assembly performance, and validation stability improvements. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Summary
Stages exact-head Hermes swap provisioning in the trusted
mainworkflow before checkout. This phase keeps the reviewed candidate helper only so the workflow change can validate under the older trusted workflow currently onmain; after this lands, a focused follow-up will remove that compatibility helper and complete the #7391 trust-boundary fix.Related Issue
Part of #7145. Security fix-forward for #7391.
Changes
workflow_dispatch,refs/heads/main, an exact trusted workflow SHA, the generated controller matrix, and explicit trusted Hermes target selection before privileged setup can run.main, the helper observes sufficient swap and exits before creating its fixed file.test/e2e/README.md.The larger-runner route cannot directly replace this fallback for exact-head validation because the trusted controller intentionally refuses candidate-selected runner labels. Pre-merge live validation executes the older trusted workflow from
main, so this rollout phase retains the reviewed candidate helper while adding the trusted pre-checkout step. After this phase lands, a focused follow-up will delete the helper and its tests; that follow-up's exact-head E2E will execute the trusted setup frommain.Type of Change
Quality Gates
test/e2e/README.md; no user-facing behavior ordocs/page changes.947375403;5874616a3and1ac224771add the requested reuse and successful-provisioning regression tests without changing runtime behavior.Documentation Writer Review
docs-updatedtest/e2e/README.mddocuments the two-phase rollout, trusted pre-checkout boundary, temporary exact-head compatibility helper, 32 GiB usable / 32 GiB + 4,096-byte allocation distinction, five bounded activation observations, fail-closed cleanup, protected lanes, and required follow-up removal; no canonical user-doc change is needed.DGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run check:diffpassed when hooks were skipped or unavailablenpm run checks,npm run typecheck:cli,npm run source-shape:check,npm run test:titles:check,npm run test:projects:check, andnpm run test-size:checkpassed.npm run docsbuilds without warnings (doc changes only)Signed-off-by: Apurv Kumaria akumaria@nvidia.com
Summary by CodeRabbit