Skip to content

fix(security): update OpenClaw to 2026.7.1 - #7280

Merged
ericksoa merged 62 commits into
mainfrom
codex/fix-openclaw-tar-audit
Jul 22, 2026
Merged

fix(security): update OpenClaw to 2026.7.1#7280
ericksoa merged 62 commits into
mainfrom
codex/fix-openclaw-tar-audit

Conversation

@jyaunches

@jyaunches jyaunches commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Summary

Updates the reviewed OpenClaw distribution from 2026.6.10 to 2026.7.1 and the sandbox Node image to 22.23.1. The image build fails closed while applying integrity-pinned remediations for vulnerable Axios copies in the Slack and Teams archives and the affected OpenTelemetry Jaeger pair in diagnostics. The separately locked mcporter@0.7.3 graph now resolves exact @hono/node-server@2.0.11 and fast-uri@3.1.4 releases and passes the reviewed audit, signature, install, and CLI checks.

The sandbox credential contract remains unchanged: generated openclaw.json contains the non-secret apiKey: "unused" sentinel, while COMPATIBLE_API_KEY remains an OpenShell provider-environment placeholder whose real value is resolved at the OpenShell boundary. No literal provider credential is persisted in OpenClaw configuration or state.

OpenClaw 2026.7.1 changed loopback shared-token CLI calls to omit the signed CLI device identity. That prevented the paired-device scope comparison from reaching the canonical scope-upgrade pairing gate. The compatibility patch now retains the signed CLI identity only after a stored operator device credential exists. The shared token still authenticates the loopback call; the paired-device record remains authoritative for scopes, and an operator.admin request must still create and receive canonical pairing approval.

The installed-base contract is covered explicitly. A pinned E2E row installs NemoClaw v0.0.89 with OpenClaw 2026.6.10 from a registry-SRI-bound frozen source archive, materializes the legacy per-agent SQLite, Memory Core, and update-check state, then upgrades in place to 2026.7.1. The current installer is deliberately not given the provider credential, so the post-upgrade turn proves reuse of the credential already held by OpenShell. The shared frozen-installer adapter also keeps the historical v0.0.36, v0.0.55, v0.0.74, and v0.0.89 matrix deterministic without weakening the current candidate.

The merge from current main preserves its Node tar@7.5.20 package fix and bundled-npm tar remediation, rebinding the affected-base guard to the upgraded Node 22.23.1 image digest. For the E2E-only OpenClaw 2026.3.11 stale-upgrade fixture, the exact reviewed source shape is verified, the replacement tar@7.5.19 archive is registry-SRI-bound, and that reviewed package is bundled into the remediated OpenClaw archive before installation. There is no completed-image scanner exception: any remaining affected copy fails the strict scan, and both stale-upgrade E2Es require the rebuilt current image inventory to be completely clean.

Changes

  • Pin OpenClaw and its first-party plugin archives to reviewed 2026.7.1 artifacts and update the Node 22.23.1 image digest.
  • Remediate only the reviewed Axios and diagnostics OTEL subtrees, with original-package identity checks, integrity pins, canonical tree digests, and archive-shape drift rejection.
  • Lock the mcporter runtime to @hono/node-server@2.0.11 and fast-uri@3.1.4; verify the script-disabled production install, registry signatures, ESM transport construction/close path, and installed CLI version.
  • Retain stored CLI device identity on loopback shared-token calls so OpenClaw's paired-device scope gate remains authoritative without moving provider secrets into OpenClaw state.
  • Preserve private device, credential, and SQLite state across startup and installed-base migrations, including bounded repair of legacy update-check state.
  • Add the frozen v0.0.89/OpenClaw 2026.6.10 to 2026.7.1 installed-base E2E row and retain the broader historical migration matrix.
  • Preserve current-main node-tar remediation, run it only after curl is installed in the DeepAgents and Hermes bases, and verify both patch helpers in the sandbox build context.
  • Exact-shape remediate the E2E-only 2026.3.11 source archive from tar@7.5.11 to a registry-SRI-bound, bundled tar@7.5.19, with the completed-image scan remaining strict and exception-free.
  • Set the authoritative local base-build allowance to 90 seconds for upgrade-head matrix runs that must build the exact local base.
  • Incorporate current main's historical Hermes fixture repair so rebuild coverage seeds, rotates, redacts, and leak-scans the required per-run API server key.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification:
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — exact head reviewed during maintainer follow-through; the implementation fails closed on package identity, archive shape, dependency graph, SRI drift, and device-scope enforcement.
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit: not applicable
  • Station profile/scenario: not applicable
  • Result: not applicable
  • Supporting evidence: not applicable

Verification

  • PR description includes Signed-off-by: lines and all new commits are SSH-signed and DCO-clean.
  • npm run checks, npm run typecheck, npm run typecheck:cli, npm run source-shape:check, and npm run test-size:check passed on the current-main reconciliation.
  • Focused combined suites passed: 258 tests with one expected skip; an independent combined run passed 61/61; the fresh real OpenClaw 2026.7.1 tarball harness passed 5/5.
  • The real upstream 2026.7.1 compiled distribution audit passed all five required compatibility-shape checks.
  • After merging current main through fix(e2e): bundle reviewed tar in legacy OpenClaw archive #7360, the focused remediation/integrity/scanner suites passed 34/34 and the installed-base migration/workflow suites passed 19/19.
  • After reconciling current main through fix(e2e): seed historical Hermes API key #7364, the exact affected Hermes historical fixture passed 9/9, the focused OpenClaw contract set passed 81 tests with one expected skip, and repository/source-shape checks passed.
  • Exact-head required GitHub CI and E2E gate are in flight.
  • No secrets, API keys, or credentials committed.

Evidence:

  • Prior upgrade-head historical evidence: five migration rows passed, including the dedicated v0.0.89/OpenClaw 2026.6.10 installed-base upgrade. Current-head coverage is also selected in the full matrix below.
  • Scope-upgrade proof on parent head 54b59af: focused run 29888373497 and the independent full-matrix cell both passed the formerly deterministic operator.admin cron path.
  • Prior-head focused rebuild coverage: run 29889345896, covering both stale OpenClaw upgrade fixtures, DeepAgents routing, and both Hermes rebuild paths.
  • Preserved prior-head full E2E evidence: run 29889347151 improved the original 66-failure/22-pass signal to 19 failures/68 passes. Every remaining red was a pre-existing DeepAgents trust-fixture failure, hosted inference capacity error, runner loss/cancellation, or transient load/SSH failure; every OpenClaw upgrade, rebuild, pairing, and installed-base migration path passed. The intermediate-head replay 29888849758 remains active append-only evidence.
  • Current exact-head append-only full matrix: run 29893928454, queued without canceling or replacing the active replay.
  • Current exact-head required CI: run 29893824224, security CodeQL 29893824206, and E2E gate 29893823011.

Signed-off-by: Julie Yaunches jyaunches@nvidia.com
Signed-off-by: Aaron Erickson aerickson@nvidia.com

Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
@jyaunches jyaunches added dependencies Pull requests that update a dependency file security labels Jul 21, 2026
@jyaunches jyaunches self-assigned this Jul 21, 2026
@coderabbitai

coderabbitai Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

OpenClaw is upgraded from 2026.6.10 to 2026.7.1 across builds, manifests, integrity metadata, compatibility patches, and tests. Selected plugin archives receive deterministic Axios remediation, while shared-state permissions, legacy cache handling, Node.js, and Docker image pins are refreshed.

Changes

OpenClaw 2026.7.1 migration

Layer / File(s) Summary
Release pins and build configuration
Dockerfile*, agents/..., ci/..., docs/security/..., nemoclaw/..., .github/...
OpenClaw, plugin, Node.js, Docker image, integrity, lifecycle, manifest, and dependency-review pins are updated to 2026.7.1.
Reviewed archive remediation
scripts/lib/openclaw-npm-remediation.mts, scripts/audit-reviewed-npm-graph.mts, src/lib/messaging/applier/...
Selected plugin archives are validated, rebuilt with patched Axios dependency graphs, repacked, integrity-checked, and passed into installation flows.
Runtime compatibility and state hardening
scripts/patch-openclaw-*.mts, scripts/validate-openclaw-tool-search.mts, scripts/nemoclaw-start.sh, scripts/lib/normalize_mutable_config_perms.py
Managed-proxy routing, follow-up run IDs, device-token scope upgrades, pairing state, tool-search handling, shared-state permissions, gateway HOME handling, and legacy update-check migration are updated.
Validation and integration coverage
test/**, tools/e2e/**, .github/workflows/**
Integrity, packaging, policy, runtime, live E2E, workflow-boundary, startup-compatibility, and device self-approval tests are updated or added.

Estimated code review effort: 5 (Critical) | ~120 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Build
  participant ArchiveRemediation
  participant OpenClawPlugin
  participant RuntimeValidation
  Build->>ArchiveRemediation: materialize reviewed plugin archive
  ArchiveRemediation->>OpenClawPlugin: patch and repack selected dependency graph
  OpenClawPlugin-->>Build: verified archive and integrity
  Build->>RuntimeValidation: install and validate pinned runtime
  RuntimeValidation-->>Build: runtime and contract results
Loading

Possibly related issues

Possibly related PRs

Suggested labels: integration: openclaw, bug-fix, area: ci, area: packaging

Suggested reviewers: senthilr-nv, ericksoa, laitingsheng

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 3.92% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: a security-focused OpenClaw version bump to 2026.7.1.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/fix-openclaw-tar-audit

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall coverage in commit b6bf757 in the codex/fix-openclaw-t... branch remains at 96%, unchanged from commit 6d0bc58 in the main branch.

TypeScript / code-coverage/cli

The overall coverage in commit b6bf757 in the codex/fix-openclaw-t... branch remains at 80%, unchanged from commit faf59fc in the main branch.

Show a code coverage summary of the most impacted files.
File main faf59fc codex/fix-openclaw-t... b6bf757 +/-
src/lib/platform.ts 89% 84% -5%
src/lib/shields/index.ts 72% 71% -1%
src/lib/state/g...way-registry.ts 94% 95% +1%
src/lib/actions...ateway-state.ts 76% 78% +2%
src/lib/state/m...-acquisition.ts 82% 84% +2%
src/lib/onboard...ndbox-create.ts 83% 91% +8%
src/lib/domain/.../connect-env.ts 89% 97% +8%
src/lib/onboard...-desktop-gpu.ts 77% 89% +12%
src/lib/onboard...-create-plan.ts 75% 88% +13%
src/lib/onboard...ndbox-create.ts 33% 83% +50%

Updated July 22, 2026 09:05 UTC

@github-actions

Copy link
Copy Markdown
Contributor

@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — Informational

Advisor assessment: Informational / medium confidence
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions
Status: No actionable findings remain in the canonical review ledger.

Model lanes

  • GPT-5.6 Terra (primary): Completed · medium confidence · 0 blockers · 0 warnings · 0 suggestions
  • Nemotron 3 Ultra (second opinion): Failed after a partial review · low confidence · 0 blockers · 10 warnings · 3 suggestions

Nemotron output stays in workflow artifacts and does not change the assessment above.

E2E guidance

Advisory only. E2E / PR Gate selects and runs jobs independently.

Recommended E2E: cloud-onboard, credential-sanitization, full-e2e, hermes-e2e, security-posture, channels-add-remove, channels-stop-start, inference-routing, issue-4462-scope-upgrade-approval, messaging-providers, network-policy, onboard-repair, onboard-resume, openclaw-tui-chat-correlation, openshell-gateway-upgrade

1 optional E2E recommendation
  • openshell-gateway-auth-contract

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/lib/messaging/applier/build/messaging-build-applier.mts`:
- Around line 1300-1307: Update the remediation call in the archive handling
flow to pass exactPackage.packageSpec unchanged as packageSpec. Remove the
appended `@exactPackage.version` suffix so remediateReviewedOpenClawPluginArchive
uses the normalized lookup key and matches REMEDIATIONS.

In `@test/openclaw-integrity-pin-suite.ts`:
- Around line 43-46: Complete the version-sensitive fixtures in
test/openclaw-integrity-pin-suite.ts: update the “newer unreviewed base” fixture
at lines 43-46 from 2026.6.11 to a version newer than 2026.7.1, such as
2026.7.2, and update its expected diagnostic; at lines 627-642, change both
optional-plugin archive-name regexes from 2026\.6\.10\.tgz to 2026\.7\.1\.tgz.
- Around line 497-502: Update the total dependency count assertion in the
reviewNote expectations to require the documented current value of 822 instead
of 818, while leaving the other dependency and severity assertions unchanged.

In `@test/openclaw-npm-remediation.test.ts`:
- Around line 77-93: Extend the remediation test around the existing shrinkwrap
assertions to also load and validate package.json, confirming axios is declared
and bundled as required. Assert the patched axios, https-proxy-agent, and
agent-base entries include the reviewed resolved URLs and SRI integrity values,
preserving the existing version and dependency checks so broken or unpinned
archives fail.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 5564a444-e868-40c2-b23a-5cb0ba739aaf

📥 Commits

Reviewing files that changed from the base of the PR and between d5fa194 and 73f88fe.

📒 Files selected for processing (58)
  • .github/actions/ci-reviewed-npm-audit/action.yaml
  • .github/workflows/candidate-compatibility.yaml
  • .github/workflows/e2e.yaml
  • Dockerfile
  • Dockerfile.base
  • agents/hermes/Dockerfile
  • agents/langchain-deepagents-code/Dockerfile.base
  • agents/openclaw/manifest.yaml
  • ci/reviewed-npm-audit.json
  • ci/reviewed-npm-lifecycle-allowlist.json
  • docs/security/openclaw-2026.7.1-dependency-review.md
  • nemoclaw-blueprint/policies/presets/weather.yaml
  • nemoclaw/package.json
  • scripts/audit-reviewed-npm-graph.mts
  • scripts/check-messaging-plan-image-boundary.mts
  • scripts/lib/openclaw-npm-remediation.mts
  • scripts/nemoclaw-start.sh
  • scripts/patch-openclaw-chat-send.mts
  • scripts/patch-openclaw-device-self-approval.mts
  • scripts/patch-openclaw-issue-4434-diagnostics.mts
  • scripts/validate-openclaw-tool-search.mts
  • src/lib/messaging/applier/build/messaging-build-applier.mts
  • src/lib/messaging/channels/discord/manifest.ts
  • src/lib/messaging/channels/metadata.test.ts
  • src/lib/messaging/channels/slack/manifest.ts
  • src/lib/messaging/channels/teams/manifest.ts
  • src/lib/messaging/channels/whatsapp/hooks/status-health.ts
  • src/lib/messaging/channels/whatsapp/manifest.ts
  • src/lib/messaging/channels/whatsapp/runtime/whatsapp-qr-compact.test.ts
  • src/lib/messaging/channels/whatsapp/runtime/whatsapp-qr-compact.ts
  • src/lib/sandbox/build-context.ts
  • test/e2e/live/messaging-providers.test.ts
  • test/e2e/live/openclaw-tui-chat-correlation.test.ts
  • test/e2e/live/openshell-gateway-auth-source-contract-helpers.ts
  • test/e2e/live/snapshot-credential-scanner.ts
  • test/e2e/support/messaging-providers-runtime-proofs.test.ts
  • test/e2e/support/openclaw-plugin-runtime-exdev-workflow-boundary.test.ts
  • test/e2e/support/openshell-gateway-auth-contract-workflow-boundary.test.ts
  • test/effective-policy-contracts.test.ts
  • test/fetch-guard-patch-regression.test.ts
  • test/helpers/fetch-guard-patch-harness.ts
  • test/helpers/openclaw-device-self-approval-patch-harness.ts
  • test/helpers/openclaw-real-device-self-approval-proof.ts
  • test/issue-4434-error-fields.test.ts
  • test/messaging-build-applier-integrity.test.ts
  • test/messaging-build-applier.test.ts
  • test/openclaw-dependency-review.test.ts
  • test/openclaw-device-self-approval-patch.test.ts
  • test/openclaw-integrity-pin-suite.ts
  • test/openclaw-lifecycle-policy.test.ts
  • test/openclaw-npm-remediation.test.ts
  • test/openclaw-optional-plugin-build.test.ts
  • test/openclaw-real-patched-dist-harness.test.ts
  • test/openclaw-tool-search-runtime-validator.test.ts
  • test/package-contract/msteams-message-hints-preload.test.ts
  • test/sandbox-build-context.test.ts
  • tools/e2e/openclaw-plugin-runtime-exdev-workflow-boundary.mts
  • tools/e2e/openshell-gateway-auth-contract-workflow-boundary.mts

Comment thread src/lib/messaging/applier/build/messaging-build-applier.mts
Comment thread test/openclaw-integrity-pin-suite.ts
Comment thread test/openclaw-integrity-pin-suite.ts Outdated
Comment thread test/openclaw-npm-remediation.test.ts
Comment thread scripts/lib/openclaw-npm-remediation.mts Fixed
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
@github-actions

Copy link
Copy Markdown
Contributor

E2E Target Results — ❌ Some tests failed

Run: 29797209133
Workflow ref: codex/fix-openclaw-tar-audit
Requested targets: (default — all supported)
Requested test IDs: (default — all default-enabled tests; explicit-only tests openshell-gateway-auth-contract, mcp-bridge-dev, hermes-gpu-startup, sandbox-rlimits-connect, and jetson-nvmap-gpu are skipped unless selected)
Summary: 16 passed, 57 failed, 0 cancelled, 5 skipped, 0 unknown

Test Result Total wall clock time
agent-turn-latency ❌ failure 10m 11s
bedrock-runtime-compatible-anthropic ❌ failure 9m 14s
bootstrap-install-smoke ❌ failure 11m 6s
brave-search ✅ success 49s
channels-add-remove ❌ failure 9m 24s
channels-stop-start ❌ failure 22m 27s
cloud-inference ❌ failure 10m 17s
cloud-onboard ❌ failure 10m 40s
common-egress-agent ❌ failure 57m 2s
concurrent-gateway-ports ❌ failure 8m 55s
credential-migration ❌ failure 9m 5s
credential-sanitization ❌ failure 9m 57s
cron-preflight-inference-local ❌ failure 10m 5s
device-auth-health ❌ failure 9m 50s
diagnostics ❌ failure 9m 37s
docs-validation ✅ success 1m 47s
double-onboard ❌ failure 9m 11s
full-e2e ❌ failure 10m 15s
gateway-drift-preflight ✅ success 41s
gateway-guard-recovery ❌ failure 9m 15s
gateway-health-honest ✅ success 47s
generate-matrix ✅ success 24s
gpu-double-onboard ❌ failure 12m 15s
gpu-e2e ❌ failure 11m 53s
hermes-dashboard ❌ failure 6m 56s
hermes-discord ❌ failure 49m 1s
hermes-e2e ✅ success 9m 11s
hermes-gpu-startup ⏭️ skipped
hermes-inference-switch ❌ failure 51m 3s
hermes-shields-config ❌ failure 6m 5s
hermes-slack ✅ success 4m 51s
inference-routing ✅ success 3m 14s
issue-2478-crash-loop-recovery ❌ failure 8m 45s
issue-4434-tui-unreachable-inference ✅ success 1m 11s
issue-4462-scope-upgrade-approval ❌ failure 10m 14s
jetson-nvmap-gpu ⏭️ skipped
kimi-inference-compat ❌ failure 9m 23s
live ❌ failure 11m 11s
mcp-bridge ❌ failure 17m 56s
mcp-bridge-dev ⏭️ skipped
messaging-compatible-endpoint ❌ failure 11m 15s
messaging-providers ❌ failure 11m 37s
model-router-provider-routed-inference ❌ failure 11m 31s
network-policy ❌ failure 9m 40s
ollama-auth-proxy ✅ success 2m 9s
onboard-negative-paths ✅ success 53s
onboard-repair ❌ failure 9m 51s
onboard-resume ❌ failure 9m 44s
openclaw-discord-pairing ❌ failure 11m 12s
openclaw-inference-switch ❌ failure 10m 10s
openclaw-plugin-runtime-exdev ✅ success 31m 3s
openclaw-skill-cli ❌ failure 9m 58s
openclaw-slack-pairing ❌ failure 10m 54s
openclaw-tui-chat-correlation ❌ failure 9m 44s
openshell-gateway-auth-contract ⏭️ skipped
openshell-gateway-upgrade ❌ failure 23m 54s
openshell-version-pin ✅ success 39s
overlayfs-autofix ✅ success 42s
rebuild-hermes ❌ failure 4m 59s
rebuild-hermes-stale-base ❌ failure 50m 1s
rebuild-openclaw ❌ failure 9m 32s
sandbox-operations ❌ failure 9m 25s
sandbox-rebuild ❌ failure 9m 13s
sandbox-rlimits-connect ⏭️ skipped
sandbox-survival ❌ failure 10m 15s
security-posture ❌ failure 14m 29s
sessions-agents-cli ❌ failure 9m 11s
shields-config ❌ failure 10m 0s
skill-agent ❌ failure 9m 23s
snapshot-commands ❌ failure 9m 54s
spark-install ❌ failure 10m 0s
state-backup-restore ❌ failure 9m 35s
telegram-injection ❌ failure 9m 50s
token-rotation ❌ failure 11m 29s
tunnel-lifecycle ❌ failure 10m 20s
ubuntu-repo-cli-smoke ✅ success 47s
upgrade-stale-sandbox ❌ failure 10m 10s
vllm-docker-storage ✅ success 49s

Explicit-only jobs skipped: openshell-gateway-auth-contract (default dispatch excludes the resource-heavy OpenShell auth-contract probe unless selected; validate with jobs=openshell-gateway-auth-contract or targets=openshell-gateway-auth-contract), mcp-bridge-dev (default dispatch excludes moving OpenShell dev artifacts unless explicitly selected; validate with jobs=mcp-bridge-dev or targets=mcp-bridge-dev), hermes-gpu-startup (default dispatch excludes this explicit-only job unless selected; validate with jobs=hermes-gpu-startup or targets=hermes-gpu-startup), sandbox-rlimits-connect (default dispatch excludes the destructive rlimit fork/connect probe unless selected; validate with jobs=sandbox-rlimits-connect or targets=sandbox-rlimits-connect), jetson-nvmap-gpu (default dispatch excludes Jetson; explicit dispatch requires allow_jetson_runner_queue=true after confirming an online Jetson runner because queued jobs do not honor timeout-minutes before assignment; validate with jobs=jetson-nvmap-gpu or targets=jetson-nvmap-gpu).

Failed tests: agent-turn-latency, bedrock-runtime-compatible-anthropic, bootstrap-install-smoke, channels-add-remove, channels-stop-start, cloud-inference, cloud-onboard, common-egress-agent, concurrent-gateway-ports, credential-migration, credential-sanitization, cron-preflight-inference-local, device-auth-health, diagnostics, double-onboard, full-e2e, gateway-guard-recovery, gpu-double-onboard, gpu-e2e, hermes-dashboard, hermes-discord, hermes-inference-switch, hermes-shields-config, issue-2478-crash-loop-recovery, issue-4462-scope-upgrade-approval, kimi-inference-compat, live, mcp-bridge, messaging-compatible-endpoint, messaging-providers, model-router-provider-routed-inference, network-policy, onboard-repair, onboard-resume, openclaw-discord-pairing, openclaw-inference-switch, openclaw-skill-cli, openclaw-slack-pairing, openclaw-tui-chat-correlation, openshell-gateway-upgrade, rebuild-hermes, rebuild-hermes-stale-base, rebuild-openclaw, sandbox-operations, sandbox-rebuild, sandbox-survival, security-posture, sessions-agents-cli, shields-config, skill-agent, snapshot-commands, spark-install, state-backup-restore, telegram-injection, token-rotation, tunnel-lifecycle, upgrade-stale-sandbox. Check the workflow run for all logs and artifacts.

ericksoa added 2 commits July 20, 2026 22:14
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
test/openclaw-integrity-pin-suite.ts (1)

461-483: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

Bind each package to its matching integrity and tarball.

These independent toContain() checks can pass even when the dependency-review note associates one package with another package’s integrity or tarball. Parse the package records, or assert each package/version/integrity/tarball tuple together, so this contract test actually validates package identity and SRI alignment.

As per path instructions, review tests for behavioral confidence rather than implementation lock-in.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/openclaw-integrity-pin-suite.ts` around lines 461 - 483, Update the
dependency-review assertions in the integrity-pin test around reviewNote so each
package’s version, integrity, and tarball are validated as one associated record
rather than through independent toContain checks. Parse the package records or
use tuple-level assertions, covering all listed OpenClaw, NemoClaw, and Codex
packages while preserving the existing pinned constants and avoiding
implementation-specific assertions.

Source: Path instructions

🧹 Nitpick comments (1)
Dockerfile (1)

587-602: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Add runtime assertions for Patch 4’s dispatcher branches.

The build check verifies only textual replacement. Add real-dist coverage proving that OpenShell plus an omitted dispatcherPolicy uses the proxy, explicit dispatcher policies retain their existing behavior, and non-OpenShell behavior is unchanged.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@Dockerfile` around lines 587 - 602, Add runtime assertions alongside the
Patch 4 validation for the real dist: verify OPENSHELL_SANDBOX=1 with an omitted
dispatcherPolicy routes through the proxy, while explicit dispatcherPolicy
values preserve their existing behavior. Also assert that non-OpenShell
execution remains unchanged, using the relevant dispatcher/fetch entry point and
existing test harness utilities.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@Dockerfile`:
- Around line 1320-1330: Update the Dockerfile state-file initialization around
the exec-approvals and SQLite paths to validate every pre-existing target before
any touch, chown, or chmod operation. Reject symlinks and hard-linked files,
using no-follow or equivalent metadata checks, and exit with the existing
unsafe-state error before modifying anything; only create or modify validated
regular files inside the intended state directory.

In `@test/openclaw-shared-state-permissions-patch.test.ts`:
- Around line 461-482: The new test conditionals violate the codebase-growth
guardrails. In test/openclaw-shared-state-permissions-patch.test.ts:461-482,
replace all manual environment save/restore if/else blocks around the test suite
with vi.stubEnv and a shared afterEach(() => vi.unstubAllEnvs()) cleanup. In
test/openclaw-2026-7-startup-compat.test.ts:125-143, replace the it.each
kind-based if/else branching with a keyed setup map, and use a nullish guard
instead of the if (!match) check near line 33.

---

Outside diff comments:
In `@test/openclaw-integrity-pin-suite.ts`:
- Around line 461-483: Update the dependency-review assertions in the
integrity-pin test around reviewNote so each package’s version, integrity, and
tarball are validated as one associated record rather than through independent
toContain checks. Parse the package records or use tuple-level assertions,
covering all listed OpenClaw, NemoClaw, and Codex packages while preserving the
existing pinned constants and avoiding implementation-specific assertions.

---

Nitpick comments:
In `@Dockerfile`:
- Around line 587-602: Add runtime assertions alongside the Patch 4 validation
for the real dist: verify OPENSHELL_SANDBOX=1 with an omitted dispatcherPolicy
routes through the proxy, while explicit dispatcherPolicy values preserve their
existing behavior. Also assert that non-OpenShell execution remains unchanged,
using the relevant dispatcher/fetch entry point and existing test harness
utilities.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: bdbd4e8e-8ddc-416c-b325-9001cfdae773

📥 Commits

Reviewing files that changed from the base of the PR and between 9317a2b and c308bcf.

⛔ Files ignored due to path filters (1)
  • nemoclaw/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (17)
  • Dockerfile
  • Dockerfile.base
  • docs/security/openclaw-2026.7.1-dependency-review.md
  • nemoclaw/package.json
  • scripts/lib/normalize_mutable_config_perms.py
  • scripts/nemoclaw-start.sh
  • scripts/patch-openclaw-shared-state-permissions.mts
  • src/lib/onboard/dockerfile-remote-dashboard-bind-contract.ts
  • src/lib/sandbox/build-context.ts
  • test/helpers/openclaw-real-device-self-approval-proof.ts
  • test/openclaw-2026-7-startup-compat.test.ts
  • test/openclaw-dependency-review.test.ts
  • test/openclaw-integrity-pin-suite.ts
  • test/openclaw-real-patched-dist-harness.test.ts
  • test/openclaw-shared-state-permissions-patch.test.ts
  • test/sandbox-build-context.test.ts
  • test/sandbox-provisioning.test.ts
🚧 Files skipped from review as they are similar to previous changes (6)
  • nemoclaw/package.json
  • test/sandbox-build-context.test.ts
  • test/openclaw-dependency-review.test.ts
  • src/lib/sandbox/build-context.ts
  • Dockerfile.base
  • test/helpers/openclaw-real-device-self-approval-proof.ts

Comment thread Dockerfile Outdated
Comment thread test/openclaw-shared-state-permissions-patch.test.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
test/openclaw-2026-7-startup-compat.test.ts (1)

122-147: 🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win

Verify rejected filesystem entries remain unchanged.

These cases currently assert only exit status 1. Also snapshot the symlink target/hardlink target and directory state, then verify they were not modified after rejection; otherwise a partial-write regression could still pass the test.

As per path instructions, test observable safety outcomes rather than only the rejection status.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/openclaw-2026-7-startup-compat.test.ts` around lines 122 - 147, Extend
the parameterized repairUpdateCheck rejection test to capture each entry’s
observable state before calling repairUpdateCheck: the symlink target’s
contents, hardlink target’s contents, or directory state as applicable. After
asserting status 1, verify the corresponding target or directory remains
unchanged, ensuring rejected symlink, hardlink, and directory paths are not
partially modified.

Source: Path instructions

🧹 Nitpick comments (2)
test/openclaw-2026-7-startup-compat.test.ts (2)

44-47: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Validate the active Dockerfile contract, not a raw substring.

A .includes("ENV ...") assertion can pass on a comment or unrelated text and does not prove the built image receives the variable. Parse the active instruction or inspect image metadata at the runtime boundary.

As per path instructions, tests should prefer observable outcomes over source-text assertions.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/openclaw-2026-7-startup-compat.test.ts` around lines 44 - 47, Update the
test case “marks direct NemoClaw containers for split-user shared state” to
validate the active Dockerfile instruction or built-image runtime metadata
instead of using a raw substring search. Ensure the assertion proves
NEMOCLAW_OPENCLAW_SHARED_STATE is actually configured in the resulting image,
while preserving the existing compatibility expectation.

Source: Path instructions


32-36: 🎯 Functional Correctness | 🔵 Trivial | 🏗️ Heavy lift

Exercise the real startup boundary instead of a regex-extracted copy.

The test extracts launch_openclaw_gateway from scripts/nemoclaw-start.sh and runs the copy, so it can pass while the script’s sourcing, environment setup, or dispatch path is broken. Prefer invoking the actual script with a fixture gateway; keep extraction only as supplemental coverage.

As per path instructions, tests should prefer observable public-boundary behavior over source-shape testing.

Also applies to: 149-191

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/openclaw-2026-7-startup-compat.test.ts` around lines 32 - 36, Update the
startup compatibility test to invoke scripts/nemoclaw-start.sh directly with a
fixture gateway and assert its observable behavior, including sourcing,
environment setup, and dispatch. Keep extractShellFunction and its isolated
launch_openclaw_gateway coverage only as supplemental testing rather than the
primary path, preserving the existing expectations where applicable.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@test/openclaw-2026-7-startup-compat.test.ts`:
- Around line 122-147: Extend the parameterized repairUpdateCheck rejection test
to capture each entry’s observable state before calling repairUpdateCheck: the
symlink target’s contents, hardlink target’s contents, or directory state as
applicable. After asserting status 1, verify the corresponding target or
directory remains unchanged, ensuring rejected symlink, hardlink, and directory
paths are not partially modified.

---

Nitpick comments:
In `@test/openclaw-2026-7-startup-compat.test.ts`:
- Around line 44-47: Update the test case “marks direct NemoClaw containers for
split-user shared state” to validate the active Dockerfile instruction or
built-image runtime metadata instead of using a raw substring search. Ensure the
assertion proves NEMOCLAW_OPENCLAW_SHARED_STATE is actually configured in the
resulting image, while preserving the existing compatibility expectation.
- Around line 32-36: Update the startup compatibility test to invoke
scripts/nemoclaw-start.sh directly with a fixture gateway and assert its
observable behavior, including sourcing, environment setup, and dispatch. Keep
extractShellFunction and its isolated launch_openclaw_gateway coverage only as
supplemental testing rather than the primary path, preserving the existing
expectations where applicable.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: bf259856-0243-4c67-b633-48b46cb1bfea

📥 Commits

Reviewing files that changed from the base of the PR and between c308bcf and 098e617.

📒 Files selected for processing (4)
  • scripts/patch-openclaw-shared-state-permissions.mts
  • test/openclaw-2026-7-startup-compat.test.ts
  • test/openclaw-real-patched-dist-harness.test.ts
  • test/openclaw-shared-state-permissions-patch.test.ts
🚧 Files skipped from review as they are similar to previous changes (3)
  • scripts/patch-openclaw-shared-state-permissions.mts
  • test/openclaw-real-patched-dist-harness.test.ts
  • test/openclaw-shared-state-permissions-patch.test.ts

@ericksoa ericksoa assigned ericksoa and unassigned jyaunches Jul 21, 2026
@github-actions

Copy link
Copy Markdown
Contributor

E2E Target Results — ❌ Some tests failed

Run: 29803628074
Workflow ref: codex/fix-openclaw-tar-audit
Requested targets: (default — all supported)
Requested test IDs: (default — all default-enabled tests; explicit-only tests openshell-gateway-auth-contract, mcp-bridge-dev, hermes-gpu-startup, sandbox-rlimits-connect, and jetson-nvmap-gpu are skipped unless selected)
Summary: 58 passed, 15 failed, 0 cancelled, 5 skipped, 0 unknown

Test Result Total wall clock time
agent-turn-latency ❌ failure 15m 12s
bedrock-runtime-compatible-anthropic ✅ success 6m 21s
bootstrap-install-smoke ✅ success 5m 52s
brave-search ✅ success 50s
channels-add-remove ❌ failure 6m 49s
channels-stop-start ❌ failure 37m 13s
cloud-inference ✅ success 6m 20s
cloud-onboard ✅ success 6m 6s
common-egress-agent ❌ failure 9m 25s
concurrent-gateway-ports ✅ success 8m 51s
credential-migration ✅ success 5m 41s
credential-sanitization ✅ success 6m 1s
cron-preflight-inference-local ✅ success 6m 20s
device-auth-health ✅ success 6m 34s
diagnostics ✅ success 6m 55s
docs-validation ✅ success 1m 52s
double-onboard ✅ success 10m 32s
full-e2e ❌ failure 6m 32s
gateway-drift-preflight ✅ success 49s
gateway-guard-recovery ✅ success 7m 52s
gateway-health-honest ✅ success 50s
generate-matrix ✅ success 27s
gpu-double-onboard ❌ failure 4m 59s
gpu-e2e ✅ success 8m 15s
hermes-dashboard ❌ failure 8m 31s
hermes-discord ✅ success 10m 0s
hermes-e2e ❌ failure 18m 2s
hermes-gpu-startup ⏭️ skipped
hermes-inference-switch ❌ failure 18m 43s
hermes-shields-config ❌ failure 8m 24s
hermes-slack ✅ success 3m 45s
inference-routing ✅ success 3m 13s
issue-2478-crash-loop-recovery ✅ success 15m 28s
issue-4434-tui-unreachable-inference ✅ success 1m 6s
issue-4462-scope-upgrade-approval ❌ failure 6m 11s
jetson-nvmap-gpu ⏭️ skipped
kimi-inference-compat ✅ success 5m 16s
live ✅ success 11m 13s
mcp-bridge ✅ success 21m 49s
mcp-bridge-dev ⏭️ skipped
messaging-compatible-endpoint ✅ success 7m 11s
messaging-providers ✅ success 14m 54s
model-router-provider-routed-inference ✅ success 8m 2s
network-policy ❌ failure 8m 45s
ollama-auth-proxy ✅ success 1m 35s
onboard-negative-paths ✅ success 58s
onboard-repair ✅ success 6m 29s
onboard-resume ✅ success 8m 4s
openclaw-discord-pairing ✅ success 7m 50s
openclaw-inference-switch ✅ success 7m 7s
openclaw-plugin-runtime-exdev ✅ success 30m 59s
openclaw-skill-cli ✅ success 6m 37s
openclaw-slack-pairing ✅ success 8m 2s
openclaw-tui-chat-correlation ❌ failure 7m 1s
openshell-gateway-auth-contract ⏭️ skipped
openshell-gateway-upgrade ✅ success 20m 54s
openshell-version-pin ✅ success 39s
overlayfs-autofix ✅ success 36s
rebuild-hermes ❌ failure 5m 30s
rebuild-hermes-stale-base ❌ failure 5m 34s
rebuild-openclaw ✅ success 9m 0s
sandbox-operations ✅ success 8m 33s
sandbox-rebuild ✅ success 6m 57s
sandbox-rlimits-connect ⏭️ skipped
sandbox-survival ✅ success 6m 33s
security-posture ✅ success 9m 4s
sessions-agents-cli ✅ success 7m 3s
shields-config ✅ success 7m 14s
skill-agent ✅ success 5m 49s
snapshot-commands ✅ success 5m 46s
spark-install ✅ success 5m 29s
state-backup-restore ✅ success 6m 39s
telegram-injection ✅ success 5m 36s
token-rotation ✅ success 20m 17s
tunnel-lifecycle ✅ success 7m 44s
ubuntu-repo-cli-smoke ✅ success 43s
upgrade-stale-sandbox ✅ success 8m 41s
vllm-docker-storage ✅ success 37s

Explicit-only jobs skipped: openshell-gateway-auth-contract (default dispatch excludes the resource-heavy OpenShell auth-contract probe unless selected; validate with jobs=openshell-gateway-auth-contract or targets=openshell-gateway-auth-contract), mcp-bridge-dev (default dispatch excludes moving OpenShell dev artifacts unless explicitly selected; validate with jobs=mcp-bridge-dev or targets=mcp-bridge-dev), hermes-gpu-startup (default dispatch excludes this explicit-only job unless selected; validate with jobs=hermes-gpu-startup or targets=hermes-gpu-startup), sandbox-rlimits-connect (default dispatch excludes the destructive rlimit fork/connect probe unless selected; validate with jobs=sandbox-rlimits-connect or targets=sandbox-rlimits-connect), jetson-nvmap-gpu (default dispatch excludes Jetson; explicit dispatch requires allow_jetson_runner_queue=true after confirming an online Jetson runner because queued jobs do not honor timeout-minutes before assignment; validate with jobs=jetson-nvmap-gpu or targets=jetson-nvmap-gpu).

Failed tests: agent-turn-latency, channels-add-remove, channels-stop-start, common-egress-agent, full-e2e, gpu-double-onboard, hermes-dashboard, hermes-e2e, hermes-inference-switch, hermes-shields-config, issue-4462-scope-upgrade-approval, network-policy, openclaw-tui-chat-correlation, rebuild-hermes, rebuild-hermes-stale-base. Check the workflow run for all logs and artifacts.

@ericksoa
ericksoa marked this pull request as ready for review July 22, 2026 06:08
Copilot AI review requested due to automatic review settings July 22, 2026 06:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@github-actions

Copy link
Copy Markdown
Contributor

E2E Target Results — ❌ Some tests failed

Run: 29888849758
Workflow ref: codex/fix-openclaw-tar-audit
Requested targets: (default — all supported)
Requested test IDs: (default — all default-enabled tests; explicit-only tests openshell-gateway-auth-contract, mcp-bridge-dev, hermes-gpu-startup, sandbox-rlimits-connect, and jetson-nvmap-gpu are skipped unless selected)
Summary: 57 passed, 16 failed, 0 cancelled, 5 skipped, 0 unknown

Test Result Total wall clock time
agent-turn-latency ❌ failure 55m 3s
bedrock-runtime-compatible-anthropic ❌ failure 51m 4s
bootstrap-install-smoke ✅ success 6m 15s
brave-search ✅ success 50s
channels-add-remove ✅ success 10m 57s
channels-stop-start ❌ failure 17m 57s
cloud-inference ✅ success 6m 49s
cloud-onboard ✅ success 7m 2s
common-egress-agent ❌ failure 9m 46s
concurrent-gateway-ports ✅ success 8m 58s
credential-migration ✅ success 5m 45s
credential-sanitization ✅ success 6m 26s
cron-preflight-inference-local ✅ success 6m 33s
device-auth-health ✅ success 6m 45s
diagnostics ✅ success 7m 29s
docs-validation ✅ success 1m 59s
double-onboard ✅ success 9m 50s
full-e2e ✅ success 6m 44s
gateway-drift-preflight ✅ success 41s
gateway-guard-recovery ✅ success 8m 14s
gateway-health-honest ✅ success 48s
generate-matrix ✅ success 22s
gpu-double-onboard ✅ success 9m 35s
gpu-e2e ✅ success 7m 17s
hermes-dashboard ❌ failure 7m 41s
hermes-discord ❌ failure 10m 12s
hermes-e2e ✅ success 44s
hermes-gpu-startup ⏭️ skipped
hermes-inference-switch ❌ failure 5m 50s
hermes-shields-config ❌ failure 10m 21s
hermes-slack ✅ success 3m 53s
inference-routing ✅ success 3m 19s
issue-2478-crash-loop-recovery ✅ success 15m 33s
issue-4434-tui-unreachable-inference ✅ success 50s
issue-4462-scope-upgrade-approval ✅ success 8m 4s
jetson-nvmap-gpu ⏭️ skipped
kimi-inference-compat ✅ success 5m 47s
live ❌ failure 8m 9s
mcp-bridge ❌ failure 24m 1s
mcp-bridge-dev ⏭️ skipped
messaging-compatible-endpoint ✅ success 6m 56s
messaging-providers ✅ success 14m 51s
model-router-provider-routed-inference ❌ failure 10m 13s
network-policy ✅ success 9m 56s
ollama-auth-proxy ✅ success 1m 17s
onboard-negative-paths ✅ success 59s
onboard-repair ✅ success 6m 31s
onboard-resume ✅ success 8m 14s
openclaw-discord-pairing ✅ success 7m 52s
openclaw-inference-switch ✅ success 7m 39s
openclaw-plugin-runtime-exdev ✅ success 23m 48s
openclaw-skill-cli ✅ success 7m 35s
openclaw-slack-pairing ✅ success 9m 12s
openclaw-tui-chat-correlation ❌ failure 8m 10s
openshell-gateway-auth-contract ⏭️ skipped
openshell-gateway-upgrade ❌ failure 59m 14s
openshell-version-pin ✅ success 40s
overlayfs-autofix ✅ success 43s
rebuild-hermes ✅ success 21m 54s
rebuild-hermes-stale-base ✅ success 21m 39s
rebuild-openclaw ❌ failure 6m 45s
sandbox-operations ✅ success 9m 4s
sandbox-rebuild ✅ success 7m 23s
sandbox-rlimits-connect ⏭️ skipped
sandbox-survival ✅ success 6m 56s
security-posture ❌ failure 6m 24s
sessions-agents-cli ✅ success 7m 8s
shields-config ✅ success 7m 55s
skill-agent ✅ success 5m 28s
snapshot-commands ✅ success 6m 3s
spark-install ✅ success 6m 5s
state-backup-restore ✅ success 7m 5s
telegram-injection ✅ success 6m 1s
token-rotation ✅ success 21m 41s
tunnel-lifecycle ✅ success 7m 14s
ubuntu-repo-cli-smoke ✅ success 35s
upgrade-stale-sandbox ❌ failure 7m 42s
vllm-docker-storage ✅ success 49s

Explicit-only jobs skipped: openshell-gateway-auth-contract (default dispatch excludes the resource-heavy OpenShell auth-contract probe unless selected; validate with jobs=openshell-gateway-auth-contract or targets=openshell-gateway-auth-contract), mcp-bridge-dev (default dispatch excludes moving OpenShell dev artifacts unless explicitly selected; validate with jobs=mcp-bridge-dev or targets=mcp-bridge-dev), hermes-gpu-startup (default dispatch excludes this explicit-only job unless selected; validate with jobs=hermes-gpu-startup or targets=hermes-gpu-startup), sandbox-rlimits-connect (default dispatch excludes the destructive rlimit fork/connect probe unless selected; validate with jobs=sandbox-rlimits-connect or targets=sandbox-rlimits-connect), jetson-nvmap-gpu (default dispatch excludes Jetson; explicit dispatch requires allow_jetson_runner_queue=true after confirming an online Jetson runner because queued jobs do not honor timeout-minutes before assignment; validate with jobs=jetson-nvmap-gpu or targets=jetson-nvmap-gpu).

Failed tests: agent-turn-latency, bedrock-runtime-compatible-anthropic, channels-stop-start, common-egress-agent, hermes-dashboard, hermes-discord, hermes-inference-switch, hermes-shields-config, live, mcp-bridge, model-router-provider-routed-inference, openclaw-tui-chat-correlation, openshell-gateway-upgrade, rebuild-openclaw, security-posture, upgrade-stale-sandbox. Check the workflow run for all logs and artifacts.

ericksoa added 2 commits July 21, 2026 23:21
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@github-actions

Copy link
Copy Markdown
Contributor

E2E Target Results — ❌ Some tests failed

Run: 29895770951
Workflow ref: codex/fix-openclaw-tar-audit
Requested targets: (default — all supported)
Requested test IDs: openshell-gateway-upgrade
Summary: 0 passed, 1 failed, 0 cancelled, 0 skipped, 0 unknown

Test Result Total wall clock time
openshell-gateway-upgrade ❌ failure 30m 32s

Failed tests: openshell-gateway-upgrade. Check the workflow run for all logs and artifacts.

ericksoa added 2 commits July 21, 2026 23:39
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@github-actions

Copy link
Copy Markdown
Contributor

E2E Target Results — ❌ Some tests failed

Run: 29897565324
Workflow ref: codex/fix-openclaw-tar-audit
Requested targets: (default — all supported)
Requested test IDs: openshell-gateway-upgrade
Summary: 0 passed, 1 failed, 0 cancelled, 0 skipped, 0 unknown

Test Result Total wall clock time
openshell-gateway-upgrade ❌ failure 20m 58s

Failed tests: openshell-gateway-upgrade. Check the workflow run for all logs and artifacts.

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@github-actions

Copy link
Copy Markdown
Contributor

E2E Target Results — ❌ Some tests failed

Run: 29893928454
Workflow ref: codex/fix-openclaw-tar-audit
Requested targets: (default — all supported)
Requested test IDs: (default — all default-enabled tests; explicit-only tests openshell-gateway-auth-contract, mcp-bridge-dev, hermes-gpu-startup, sandbox-rlimits-connect, and jetson-nvmap-gpu are skipped unless selected)
Summary: 52 passed, 18 failed, 3 cancelled, 5 skipped, 0 unknown

Test Result Total wall clock time
agent-turn-latency ❌ failure 10m 44s
bedrock-runtime-compatible-anthropic ❌ failure 6m 20s
bootstrap-install-smoke ✅ success 6m 8s
brave-search ✅ success 46s
channels-add-remove ✅ success 10m 45s
channels-stop-start ❌ failure 18m 15s
cloud-inference ✅ success 6m 42s
cloud-onboard ✅ success 7m 3s
common-egress-agent ❌ failure 9m 16s
concurrent-gateway-ports ✅ success 11m 47s
credential-migration ✅ success 5m 42s
credential-sanitization ✅ success 7m 23s
cron-preflight-inference-local ⚠️ cancelled 55m 0s
device-auth-health ✅ success 6m 35s
diagnostics ✅ success 6m 53s
docs-validation ✅ success 1m 55s
double-onboard ❌ failure 51m 1s
full-e2e ✅ success 7m 3s
gateway-drift-preflight ✅ success 48s
gateway-guard-recovery ❌ failure 7m 48s
gateway-health-honest ✅ success 38s
generate-matrix ✅ success 29s
gpu-double-onboard ✅ success 8m 2s
gpu-e2e ✅ success 8m 22s
hermes-dashboard ❌ failure 51m 2s
hermes-discord ❌ failure 15m 54s
hermes-e2e ❌ failure 4m 54s
hermes-gpu-startup ⏭️ skipped
hermes-inference-switch ❌ failure 18m 42s
hermes-shields-config ⚠️ cancelled 55m 1s
hermes-slack ✅ success 4m 0s
inference-routing ✅ success 3m 13s
issue-2478-crash-loop-recovery ✅ success 16m 2s
issue-4434-tui-unreachable-inference ✅ success 1m 0s
issue-4462-scope-upgrade-approval ✅ success 8m 26s
jetson-nvmap-gpu ⏭️ skipped
kimi-inference-compat ⚠️ cancelled 55m 1s
live ❌ failure 7m 48s
mcp-bridge ❌ failure 11m 36s
mcp-bridge-dev ⏭️ skipped
messaging-compatible-endpoint ✅ success 6m 52s
messaging-providers ✅ success 14m 40s
model-router-provider-routed-inference ✅ success 9m 38s
network-policy ✅ success 9m 23s
ollama-auth-proxy ✅ success 1m 23s
onboard-negative-paths ✅ success 56s
onboard-repair ✅ success 6m 17s
onboard-resume ✅ success 7m 33s
openclaw-discord-pairing ❌ failure 22m 44s
openclaw-inference-switch ✅ success 8m 13s
openclaw-plugin-runtime-exdev ✅ success 31m 5s
openclaw-skill-cli ✅ success 7m 25s
openclaw-slack-pairing ✅ success 9m 16s
openclaw-tui-chat-correlation ✅ success 6m 51s
openshell-gateway-auth-contract ⏭️ skipped
openshell-gateway-upgrade ❌ failure 3m 6s
openshell-version-pin ✅ success 1m 13s
overlayfs-autofix ✅ success 45s
rebuild-hermes ✅ success 40m 47s
rebuild-hermes-stale-base ❌ failure 1h 18m 9s
rebuild-openclaw ❌ failure 6m 33s
sandbox-operations ✅ success 10m 1s
sandbox-rebuild ✅ success 7m 4s
sandbox-rlimits-connect ⏭️ skipped
sandbox-survival ✅ success 17m 41s
security-posture ❌ failure 6m 40s
sessions-agents-cli ✅ success 7m 43s
shields-config ✅ success 7m 32s
skill-agent ✅ success 5m 54s
snapshot-commands ✅ success 7m 14s
spark-install ✅ success 6m 24s
state-backup-restore ✅ success 7m 7s
telegram-injection ✅ success 7m 24s
token-rotation ✅ success 21m 36s
tunnel-lifecycle ✅ success 7m 9s
ubuntu-repo-cli-smoke ✅ success 38s
upgrade-stale-sandbox ❌ failure 7m 38s
vllm-docker-storage ✅ success 49s

Explicit-only jobs skipped: openshell-gateway-auth-contract (default dispatch excludes the resource-heavy OpenShell auth-contract probe unless selected; validate with jobs=openshell-gateway-auth-contract or targets=openshell-gateway-auth-contract), mcp-bridge-dev (default dispatch excludes moving OpenShell dev artifacts unless explicitly selected; validate with jobs=mcp-bridge-dev or targets=mcp-bridge-dev), hermes-gpu-startup (default dispatch excludes this explicit-only job unless selected; validate with jobs=hermes-gpu-startup or targets=hermes-gpu-startup), sandbox-rlimits-connect (default dispatch excludes the destructive rlimit fork/connect probe unless selected; validate with jobs=sandbox-rlimits-connect or targets=sandbox-rlimits-connect), jetson-nvmap-gpu (default dispatch excludes Jetson; explicit dispatch requires allow_jetson_runner_queue=true after confirming an online Jetson runner because queued jobs do not honor timeout-minutes before assignment; validate with jobs=jetson-nvmap-gpu or targets=jetson-nvmap-gpu).

Failed tests: agent-turn-latency, bedrock-runtime-compatible-anthropic, channels-stop-start, common-egress-agent, double-onboard, gateway-guard-recovery, hermes-dashboard, hermes-discord, hermes-e2e, hermes-inference-switch, live, mcp-bridge, openclaw-discord-pairing, openshell-gateway-upgrade, rebuild-hermes-stale-base, rebuild-openclaw, security-posture, upgrade-stale-sandbox. Check the workflow run for all logs and artifacts.

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@github-actions

Copy link
Copy Markdown
Contributor

E2E Target Results — ❌ Some tests failed

Run: 29898253764
Workflow ref: codex/fix-openclaw-tar-audit
Requested targets: (default — all supported)
Requested test IDs: (default — all default-enabled tests; explicit-only tests openshell-gateway-auth-contract, mcp-bridge-dev, hermes-gpu-startup, sandbox-rlimits-connect, and jetson-nvmap-gpu are skipped unless selected)
Summary: 59 passed, 13 failed, 1 cancelled, 5 skipped, 0 unknown

Test Result Total wall clock time
agent-turn-latency ❌ failure 10m 49s
bedrock-runtime-compatible-anthropic ❌ failure 49m 0s
bootstrap-install-smoke ✅ success 6m 16s
brave-search ✅ success 50s
channels-add-remove ✅ success 10m 39s
channels-stop-start ❌ failure 52m 15s
cloud-inference ✅ success 6m 34s
cloud-onboard ✅ success 7m 6s
common-egress-agent ❌ failure 9m 22s
concurrent-gateway-ports ✅ success 6m 43s
credential-migration ✅ success 5m 38s
credential-sanitization ✅ success 6m 18s
cron-preflight-inference-local ✅ success 6m 38s
device-auth-health ✅ success 6m 36s
diagnostics ✅ success 6m 51s
docs-validation ✅ success 1m 58s
double-onboard ✅ success 9m 57s
full-e2e ✅ success 6m 37s
gateway-drift-preflight ✅ success 44s
gateway-guard-recovery ⚠️ cancelled 55m 1s
gateway-health-honest ✅ success 44s
generate-matrix ✅ success 29s
gpu-double-onboard ✅ success 9m 13s
gpu-e2e ✅ success 8m 12s
hermes-dashboard ❌ failure 4m 52s
hermes-discord ❌ failure 7m 1s
hermes-e2e ❌ failure 5m 6s
hermes-gpu-startup ⏭️ skipped
hermes-inference-switch ❌ failure 6m 53s
hermes-shields-config ❌ failure 17m 50s
hermes-slack ✅ success 3m 42s
inference-routing ✅ success 3m 15s
issue-2478-crash-loop-recovery ✅ success 15m 55s
issue-4434-tui-unreachable-inference ✅ success 54s
issue-4462-scope-upgrade-approval ✅ success 8m 38s
jetson-nvmap-gpu ⏭️ skipped
kimi-inference-compat ✅ success 13m 23s
live ✅ success 10m 21s
mcp-bridge ❌ failure 26m 14s
mcp-bridge-dev ⏭️ skipped
messaging-compatible-endpoint ❌ failure 6m 59s
messaging-providers ✅ success 15m 29s
model-router-provider-routed-inference ✅ success 9m 42s
network-policy ✅ success 9m 53s
ollama-auth-proxy ✅ success 1m 48s
onboard-negative-paths ✅ success 52s
onboard-repair ✅ success 6m 45s
onboard-resume ✅ success 7m 55s
openclaw-discord-pairing ✅ success 10m 2s
openclaw-inference-switch ✅ success 7m 27s
openclaw-plugin-runtime-exdev ✅ success 29m 42s
openclaw-skill-cli ✅ success 6m 45s
openclaw-slack-pairing ✅ success 8m 48s
openclaw-tui-chat-correlation ✅ success 6m 30s
openshell-gateway-auth-contract ⏭️ skipped
openshell-gateway-upgrade ✅ success 21m 22s
openshell-version-pin ✅ success 40s
overlayfs-autofix ✅ success 45s
rebuild-hermes ✅ success 25m 57s
rebuild-hermes-stale-base ✅ success 20m 43s
rebuild-openclaw ✅ success 9m 53s
sandbox-operations ✅ success 9m 3s
sandbox-rebuild ❌ failure 23m 5s
sandbox-rlimits-connect ⏭️ skipped
sandbox-survival ✅ success 6m 58s
security-posture ❌ failure 24m 3s
sessions-agents-cli ✅ success 7m 28s
shields-config ✅ success 7m 44s
skill-agent ✅ success 5m 54s
snapshot-commands ✅ success 6m 59s
spark-install ✅ success 6m 18s
state-backup-restore ✅ success 6m 47s
telegram-injection ✅ success 6m 49s
token-rotation ✅ success 19m 46s
tunnel-lifecycle ✅ success 7m 10s
ubuntu-repo-cli-smoke ✅ success 48s
upgrade-stale-sandbox ✅ success 10m 22s
vllm-docker-storage ✅ success 45s

Explicit-only jobs skipped: openshell-gateway-auth-contract (default dispatch excludes the resource-heavy OpenShell auth-contract probe unless selected; validate with jobs=openshell-gateway-auth-contract or targets=openshell-gateway-auth-contract), mcp-bridge-dev (default dispatch excludes moving OpenShell dev artifacts unless explicitly selected; validate with jobs=mcp-bridge-dev or targets=mcp-bridge-dev), hermes-gpu-startup (default dispatch excludes this explicit-only job unless selected; validate with jobs=hermes-gpu-startup or targets=hermes-gpu-startup), sandbox-rlimits-connect (default dispatch excludes the destructive rlimit fork/connect probe unless selected; validate with jobs=sandbox-rlimits-connect or targets=sandbox-rlimits-connect), jetson-nvmap-gpu (default dispatch excludes Jetson; explicit dispatch requires allow_jetson_runner_queue=true after confirming an online Jetson runner because queued jobs do not honor timeout-minutes before assignment; validate with jobs=jetson-nvmap-gpu or targets=jetson-nvmap-gpu).

Failed tests: agent-turn-latency, bedrock-runtime-compatible-anthropic, channels-stop-start, common-egress-agent, hermes-dashboard, hermes-discord, hermes-e2e, hermes-inference-switch, hermes-shields-config, mcp-bridge, messaging-compatible-endpoint, sandbox-rebuild, security-posture. Check the workflow run for all logs and artifacts.

@ericksoa

Copy link
Copy Markdown
Contributor

Maintainer acceptance for exact head b6bf7570fd5bcd6487fa81a32a334425c1f1224e against base/main 6e70994f9a53e5220264c3f538dc40baa3b2b1ca:

I accept these non-success checks as maintainer for this exact head/base pair. They do not provide regression evidence against the narrow OpenClaw credential-boundary or installed-base migration fix. Proceeding with an exact-head guarded admin squash merge.

@ericksoa
ericksoa merged commit 059f328 into main Jul 22, 2026
54 of 58 checks passed
@ericksoa
ericksoa deleted the codex/fix-openclaw-tar-audit branch July 22, 2026 10:07
ericksoa added a commit that referenced this pull request Jul 22, 2026
## Summary

- Keep the installer production contract unchanged: relative OpenShell
overrides are resolved to an absolute physical path with `pwd -P`.
- Make the focused test assert the actual contract: the watcher receives
an absolute path resolving to the same executable.
- Accept the standard macOS `/var` to `/private/var` canonicalization.

## Why

The post-merge main platform watch failed only because the test compared
path spellings lexically. The identical assertion failed on the
immediately previous completed main-watch run and on the first completed
run after the test was introduced, so this was not introduced by #7280.

Evidence:
https://github.com/NVIDIA/NemoClaw/actions/runs/29910675239/job/88892568917
and
https://github.com/NVIDIA/NemoClaw/actions/runs/29897085188/job/88849484779

## Verification

- `CI=1 npx vitest run --project cli
src/lib/actions/uninstall/hermes-forward-watcher-installer.test.ts
--reporter=verbose`
- `npx @biomejs/biome check
src/lib/actions/uninstall/hermes-forward-watcher-installer.test.ts`
- `npm run build:cli && npm run typecheck`
- `git diff --check`

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Updated coverage to verify that the Hermes forward watcher logs an
absolute OpenShell path.
* Confirmed the logged path resolves to the same filesystem target as
the generated executable.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@cv cv mentioned this pull request Jul 22, 2026
22 tasks
cv added a commit that referenced this pull request Jul 22, 2026
<!-- markdownlint-disable MD041 -->
## Summary

Adds the canonical `## v0.0.92` release entry to
`docs/changelog/2026-07-22.mdx` before the release plan is generated.
The entry summarizes all ten pull requests merged after v0.0.91,
including the OpenClaw security update and Jaeger runtime regression
coverage.

## Changes

- Added the canonical v0.0.92 changelog entry.
- Recorded the user-visible, security, documentation, CI, and test
changes in the release range.
- #7280 -> `docs/changelog/2026-07-22.mdx`: OpenClaw 2026.7.1 and
Node.js 22.23.1 security/runtime update.
- #7378 -> `docs/changelog/2026-07-22.mdx`: canonical macOS watcher path
validation.
- #7379 -> `docs/changelog/2026-07-22.mdx`: stabilized full WSL platform
validation.
- #7380 -> `docs/changelog/2026-07-22.mdx`: bounded swap for hosted
Hermes image exports.
- #7100 -> `docs/changelog/2026-07-22.mdx`: semantic progress phases for
live E2E tests.
- #7376 -> `docs/changelog/2026-07-22.mdx`: restored v0.0.91 changelog
history and corrected tagged guidance.
- #7374 -> `docs/changelog/2026-07-22.mdx`: reviewed Homebrew formula
transition for installer integrity checks.
- #7346 -> `docs/changelog/2026-07-22.mdx`: provider-neutral headless
server deployment guidance.
- #7381 -> `docs/changelog/2026-07-22.mdx`: stabilized Hermes guard
timing and WSL ownership fixtures.
- #7339 -> `docs/changelog/2026-07-22.mdx`: real-artifact Jaeger header
remediation regression coverage.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [x] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [ ] Tests added or updated for changed behavior
- [x] Existing tests cover changed behavior — justification:
`test/changelog-docs.test.ts` validates the canonical dated changelog
and release heading contract.
- [ ] Tests not applicable — justification:
- [x] Docs updated for user-facing behavior changes
- [ ] Docs not applicable — justification:
- [ ] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [ ] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification:
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit: Not applicable
- Station profile/scenario: Not applicable
- Result: Not applicable
- Supporting evidence: Not applicable

## Verification

- [x] PR description includes a `Signed-off-by:` line and every commit
appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or
`npm run check:diff` passed when hooks were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests
are marked not applicable above — `npx vitest run
test/changelog-docs.test.ts` passed 6/6 tests.
- [ ] Applicable broad gate passed — `npm test` for broad
runtime/test-harness changes; `npm run check` for repo-wide
validation/coverage changes — command/result: Not applicable to a
changelog-only change.
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only) — passed
with 0 errors and 2 pre-existing Fern warnings.
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

---
Signed-off-by: Carlos Villela <cvillela@nvidia.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added `v0.0.92` release notes covering sandboxing updates
(OpenClaw/Node.js bumps, integrity pinning remediation, mcporter
handling, and upgrade validation).
* Updated deployment guidance for provider-neutral headless installs,
and improved live E2E test reporting plus phase-plan validation.
* Tightened installer integrity-check messaging during an OpenShell
Homebrew transition and expanded platform/image validation (including
macOS/WSL timing) and hosted image export behavior.
* Restored the previously missed `v0.0.91` changelog entry and release
validation guidance.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: Carlos Villela <cvillela@nvidia.com>
cv added a commit that referenced this pull request Jul 23, 2026
<!-- markdownlint-disable MD041 -->
## Summary

#7100 established semantic phase coverage for all live E2E cases. This
follow-up closes the remaining contract gaps without reapplying that
implementation: it covers workflow-selected credential-free integration
tests, requires E2E child-process boundaries to expose content-free
liveness, and blocks OpenShell gateway-auth artifact uploads unless a
fail-closed safety scan approves the current run attempt. Together with
#7100, this completes #7101 while preserving current `main` behavior in
the audited overlap areas.

## Related Issue

Fixes #7101

## Changes

- Strengthen the shared progress contract with a frozen canonical
capability, target/scenario identity, total and phase elapsed time,
validated content-free events and activities, timestamp-only
child-output observations, and final-phase enforcement.
- Add `spawnObservedChild` as the audited direct asynchronous process
boundary used by E2E helpers. The semantic checker rejects unaudited
direct process APIs and requires synchronous calls to use a bounded
timeout plus `SIGKILL`.
- Add the lightweight `workflow-e2e-test` fixture for credential-free
integration tests selected by the authoritative E2E planner, so they
publish and validate the same semantic timeline and progress artifact
contract without the stateful live fixture.
- Convert the remaining agent-turn, Bedrock, Ollama, inference-routing,
runtime-override, fake-server, Docker, and cleanup process paths to
progress-aware boundaries without forwarding child stdout or stderr
contents.
- Scan final OpenShell gateway-auth artifacts before upload in both main
and candidate workflows. Unsafe files are quarantined or deleted, and
upload requires a run-ID/run-attempt-specific approval marker so a stale
or failed scan cannot authorize publication.
- Expand semantic coverage tests, workflow-boundary tests, pre-commit
routing, and contributor/E2E documentation for these additional
enforcement boundaries.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [x] Code change with doc updates
- [ ] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates
<!-- Check one tests line and one docs line. Check other lines when
applicable. Add every requested justification or approval reference. -->
- [x] Tests added or updated for changed behavior
- [ ] Existing tests cover changed behavior — justification:
- [ ] Tests not applicable — justification:
- [x] Docs updated for user-facing behavior changes
- [ ] Docs not applicable — justification:
- [x] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [x] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification: An independent
clean-delta and rollback audit confirmed that #7100 behavior remains
intact, all 13 previously identified #7280-sensitive paths preserve
current `main`, the Hermes shard implementations are unchanged, and the
gateway-auth scanner/upload path fails closed. Focused scanner and
workflow-boundary tests pass on the rebased commit.
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## DGX Station Hardware Evidence
<!-- Required only when scripts/prepare-dgx-station-host.sh changes.
Maintainers must review the linked evidence before approving or merging.
This is human-reviewed evidence, not authenticated hardware provenance.
Exceptional bypasses use existing repository governance and must be
documented on the PR. -->
- [ ] Tested on DGX Station
- Tested commit:
- Station profile/scenario:
- Result:
- Supporting evidence:

## Verification
<!-- Check each applicable item only when supported by the requested
evidence. Run targeted tests once per relevant change set and rerun
after later edits or hook autofixes that can affect the tested behavior.
Do not rerun hook-covered checks. -->
- [x] PR description includes a `Signed-off-by:` line and every commit
appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or
`npm run check:diff` passed when hooks were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests
are marked not applicable above — rebased final-head E2E-support suite:
17 files and 150/150 tests passed; `npm run test:e2e-phases:check`: 123
tests across 82 files passed; selected integration suite: 6 files passed
and 1 skipped, with 37 tests passed and 3 skipped; CLI and plugin
type-checks, CLI build, and diff checks passed
- [ ] Applicable broad gate passed — `npm test` for broad
runtime/test-harness changes; `npm run check` for repo-wide
validation/coverage changes — local `npm run check` completed the full
pre-commit stage, but its intentionally serial CLI/integration coverage
lane reached the four-hour execution ceiling before producing a final
summary; required sharded CI is authoritative
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only) — passed
with 0 errors and 2 existing Fern warnings
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

---
<!-- DCO sign-off is required in this PR description, and every commit
must appear as Verified in GitHub. Run: git config user.name && git
config user.email -->
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added structured, redacted progress reporting across E2E phases and
workflow-selected credential-free integration tests.
* Introduced an OpenShell gateway auth artifact safety scan that
produces an approved payload and gates evidence/artifact uploads.

* **Bug Fixes**
* Prevented sensitive values from appearing in progress output and
persisted artifacts; uploads now proceed only after safety approval
succeeds.
* Hardened E2E subprocess lifecycle handling with forced termination,
bounded output capture, and safer shutdown behavior.

* **Documentation**
* Updated E2E phase-plan/progress and artifact-safety guidance,
including the `test:e2e-phases:check` contract.

* **Tests**
* Expanded coverage for progress reporting, observed subprocess
lifecycle, and workflow/semantic-phase boundary rules.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

## Documentation Writer Review
- [x] Documentation writer subagent reviewed the completed changes
- Result: `docs-updated`
- Evidence: `CONTRIBUTING.md`, `test/e2e/README.md`,
`test/e2e/docs/README.md`
- Agent: Codex Desktop
- PR: #7397
<!-- docs-review-head-sha: bd75ae8 -->
<!-- docs-review-agents-blob-sha: 560ff38 -->

---------

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Co-authored-by: Carlos Villela <cvillela@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants