test(e2e): keep calibration ancestry durable - #8023
Conversation
📝 WalkthroughWalkthroughThe startup calibration schema test now requires five distinct tested SHAs. It validates ancestry through ChangesCalibration test validation
Estimated code review effort: 1 (Trivial) | ~5 minutes Suggested labels: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Exact-head security and provenance reviewPASS at The change removes only a local ancestry lookup for
File reviewed: |
PR Review Advisor — No blocking findings reportedAdvisor assessment: No blocking advisor findings reported Model lanes
Second-opinion E2E selections are advisory. They do not change the primary assessment or E2E / PR Gate. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: None 1 optional E2E recommendation
This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit a984a48 in the TypeScript / code-coverage/cliThe overall coverage in commit a984a48 in the Show a code coverage summary of the most impacted files.
Updated |
<!-- markdownlint-disable MD041 --> ## Summary Adds the canonical dated changelog entry for `v0.0.100` so the maintainer release plan can verify the pre-tag documentation prerequisite. The entry summarizes the user-facing changes merged since `v0.0.99` and links to the relevant guides. ## Changes - Add `docs/changelog/2026-07-31.mdx` with the exact `## v0.0.100` heading. - Cover restored OpenClaw pairing, transactional replacement, Deep Agents Code, onboarding recovery, lifecycle cleanup, Hermes builds, host provenance, documentation, and trusted E2E evidence. - Distinguish active Docker and Kubernetes runtime-bundle enforcement from the still-inactive managed shared-state transaction foundation. ## Source Coverage The release entry maps the doc-impacting merged PRs in the `v0.0.99..main` release range to `docs/changelog/2026-07-31.mdx`: #8021, #8024, #7973, #8028, #7947, #7788, #7884, #8023, #7969, #8020, #7989, #8000, #7907, #7942, #7567, #8013, #7955, #8017, #8014, #8015, #7629, #7644, #7821, #7971, and #7991. PR #7974 was reviewed after the final rebase and excluded because it changes internal maintainer-skill attribution policy and tests only; it does not change a user-facing product or documentation surface. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: the changelog contract test validates the dated entry, version heading, SPDX form, and route constraints. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: `docs/changelog/2026-07-31.mdx`; exact-head review passed for `6093f44f`; writing rules and documentation style reviewed; `npx vitest run test/changelog-docs.test.ts` passed 6/6; `npm run docs` passed with zero Fern errors and two generic Fern upgrade notices. - Agent: Codex Desktop <!-- docs-review-head-sha: 6093f44 --> <!-- docs-review-agents-blob-sha: 3dd7c24 --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable; no DGX Station host script changed. - Station profile/scenario: Not applicable. - Result: Not applicable. - Supporting evidence: Not applicable. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run validate:pr` passed after refreshing `origin/main` when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: `npx vitest run test/changelog-docs.test.ts` passed 6/6 at `6093f44f`. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to a dated prose-only release entry. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — validation passed with zero errors; Fern emitted two generic upgrade notices. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — the changelog entry has the required parser-safe MDX SPDX header; dated changelog entries intentionally do not use page frontmatter. --- Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added release notes for v0.0.100. * Documented improvements to restore pairing, sandbox replacement, onboarding recovery, lifecycle cleanup, runtime handling, build support, host readiness, and end-to-end validation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary `hermes status` reported a running foreground gateway as stopped because NemoClaw renames the managed entrypoint to `hermes.real`, while Hermes recognized only `hermes` and `hermes.exe`. This change applies a SHA-pinned, exact-shape image patch that recognizes NemoClaw's managed basename without changing Hermes's gateway subcommand grammar. ## Related Issue Closes #7804. ## Changes - Add an idempotent image-time patcher that adds `hermes.real` to Hermes's gateway entry-token allowlist and fails on upstream source-shape drift. - Pin and apply the patcher in the Hermes image, then probe the real installed matcher during the image build. - Register the installed matcher assertion in the checked-in image probe runner so BuildKit and legacy OpenShell gateway builders execute the same proof. - Test the renamed and upstream entrypoints, both detection paths, negative subcommands, look-alike basenames, idempotence, source drift, payload placement, and digest synchronization. - Classify the build-only patcher SHA as an integrity pin in the managed-startup Docker input inventory required by current `main`. ## Type of Change - [x] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [ ] Docs updated for user-facing behavior changes - [x] Docs not applicable — justification: The change restores existing direct Hermes process detection. It does not change documented host commands, configuration, workflows, defaults, or lifecycle behavior. - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [x] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: Codex Desktop security review passed all nine repository categories for exact head `504b365f2da5fcb8581edfba724e02686f30faa0`; refer to the [exact-head agent review evidence](#7885 (comment)). - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Exact-State Evidence - PR SHA: `504b365f2da5fcb8581edfba724e02686f30faa0`. - Base SHA: `299050fc0563db0cd3a803298a6fb986dcfbb745` from `upstream/main`. - Refresh: signed merge commit `504b365f2da5fcb8581edfba724e02686f30faa0` preserves both signed canonical-base refresh `9a42cffe6af5e4944207b3c5bb3badba15099171` and concurrent GitHub Verified branch update `f1cfeb15a63ab6f529fe1883c1cc1bb919b0ea6c`. Both parents have the same tree and integrate tested base `299050fc0563db0cd3a803298a6fb986dcfbb745`, so the push remains fast-forward and non-force. - Current-main integration: signed commit `8c673831c0a48f3aed0f40efad1b4af64a0b5475` routes the unchanged installed matcher assertions through current main's builder-independent Hermes probe runner. The complete seven-file diff has stable patch ID `da20cca51b92f870fbe7fb713ed07bc4066bf01d`. - Current-base regression: `test(e2e): keep calibration ancestry durable (#8023)` at `299050fc0` fixes the unrelated orphaned closed-PR calibration reference that failed the preceding required CLI shard. The refreshed calibration contract passes 14/14; no evidence from that failed head/base pair is reused. - Product-scope gate: **PASS**, independently of GitHub merge state. The PR fixes issue #7804 in the existing Tested Hermes agent surface documented in `docs/reference/platform-support.mdx`. It adds no integration, configuration, lifecycle, ownership, or compatibility surface. - Contributor compliance: the PR includes the contributor's DCO declaration. All eighteen displayed commits must remain GitHub Verified at the final gate. ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `no-docs-needed` - Evidence: No documentation or Fern paths changed. The review covered the seven-file exact-head diff, comments, docstrings, probe naming, test titles, terminology, structure, voice, and code-sample presentation. Focused and calibration regression tests passed 160/160, all diff-aware hook stages passed, and `git diff --check` passed. - Agent: Codex Desktop <!-- docs-review-head-sha: 504b365 --> <!-- docs-review-agents-blob-sha: c052d60 --> ## DGX Station Hardware Evidence <!-- Required only when scripts/prepare-dgx-station-host.sh changes. Maintainers must review the linked evidence before approving or merging. This is human-reviewed evidence, not authenticated hardware provenance. Exceptional bypasses use existing repository governance and must be documented on the PR. --> - [ ] Tested on DGX Station - Tested commit: Not applicable; this PR does not change `scripts/prepare-dgx-station-host.sh`. - Station profile/scenario: Not applicable. - Result: Not applicable. - Supporting evidence: Not applicable. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run validate:pr` passed after refreshing `origin/main` when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: the seven-file Hermes patch, probe-runner, image-layout, managed-startup, profile-policy, cron-runtime, Discord-recovery, and refreshed calibration regression suite passed 160/160 on `504b365f2`; the security specialist also passed 132/132 exact-head Hermes/image and managed profile contracts. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable; the exact image patcher, checked-in probe runner, image-layout, and Docker input inventory contracts are covered by the focused suite and exact-head CI. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) - [ ] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Yanyun Liao <yanyunl@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved Hermes gateway detection for renamed entrypoints and supported runtime commands. * Prevented false positives from lookalike or unrelated commands. * **Reliability** * Added validation to ensure the gateway patch is applied safely and consistently. * Added integrity checks and image-build probes to verify the behavior automatically. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Yanyun Liao <yanyunl@nvidia.com> Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com> Co-authored-by: Senthil Ravichandran <senthilr@nvidia.com>
Summary
Calibration validation now uses only durable workflow revisions for local Git ancestry. Exact tested revisions remain bound to their run and job receipts, but closing an evidence-source PR no longer breaks unrelated CI when its ref disappears.
Related Issue
Fixes #8022.
Changes
testedSha, run ID, job ID, and run URL receipt validation and require five distinct tested revisions.Type of Change
Quality Gates
Documentation Writer Review
no-docs-neededDGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run validate:prpassed after refreshingorigin/mainwhen hooks were skipped or unavailablenpx vitest run test/onboard-performance-config-schema.test.tspasses 14/14 afterward. Repository, project-membership, source-shape, test-size, Biome, and diff checks pass.npm testfor broad runtime/test-harness changes;npm run checkfor repo-wide validation/coverage changes — command/result: Required PR CI is pending.npm run docsbuilds without warnings (doc changes only)Signed-off-by: Prekshi Vyas prekshiv@nvidia.com
Summary by CodeRabbit