Skip to content

fix(e2e): paginate stale dispatch receipt rechecks - #7595

Merged
cv merged 3 commits into
mainfrom
codex/7593-stale-receipt-pagination
Jul 26, 2026
Merged

fix(e2e): paginate stale dispatch receipt rechecks#7595
cv merged 3 commits into
mainfrom
codex/7593-stale-receipt-pagination

Conversation

@apurvvkumaria

@apurvvkumaria apurvvkumaria commented Jul 26, 2026

Copy link
Copy Markdown
Collaborator

Summary

Follow up on #7594 so an old dispatch-not-observed receipt can be rechecked after more than one page of matching workflow runs. The recheck now reads a complete, bounded inventory without hiding late children or permitting a duplicate dispatch.

Related Issue

Follow-up to #7594 for #7593.
Part of #7140.

Changes

  • Paginate stale-receipt workflow inventories through GitHub's documented 1,000-result filtered-search limit under one shared timeout.
  • Require a stable total count, complete intermediate pages, exact final count, and globally unique run IDs before replacement can proceed.
  • Preserve fail-closed behavior for changing, duplicate, short, oversized, timed-out, or otherwise incomplete inventories.
  • Share the request-ID validator and reconciliation-window limit between receipt production and validation.
  • Centralize the exact pre-dispatch titles consumed by the producer and fail-closed validator.

The direct time-window cap suggested during review was not used because it could hide a genuinely late child. Tests cover a clean 101-run inventory, a correlated child appearing only on page two, and every incomplete-inventory rejection boundary.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification: this is an internal E2E control-plane reliability follow-up; the operational guidance added by fix(e2e): reconcile uncertain workflow dispatches #7594 remains accurate.
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: independent Codex security and code reviews passed at 0693c168d; pagination remains bounded, complete, and fail-closed before any replacement dispatch.
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: no-docs-needed
  • Evidence: fix(e2e): reconcile uncertain workflow dispatches #7594's test/e2e/README.md and .agents/skills/nemoclaw-maintainer-day/MERGE-GATE.md guidance remains accurate; no user-facing docs/ behavior changes.
  • Agent: Codex Desktop

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit:
  • Station profile/scenario:
  • Result:
  • Supporting evidence:

Verification

  • PR description includes a Signed-off-by: line and every commit appears as Verified in GitHub
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run check:diff passed when hooks were skipped or unavailable
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — npx vitest run --project integration test/github-api.test.ts test/pr-e2e*.test.ts: 19 files, 311 tests passed
  • Applicable broad gate passed — CLI type-check and npx prek run --from-ref origin/main --to-ref HEAD passed
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, or credentials committed
  • npm run docs builds without warnings (doc changes only)
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

Signed-off-by: Apurv Kumaria akumaria@nvidia.com

Summary by CodeRabbit

  • Bug Fixes

    • Improved dispatch reconciliation when workflow runs appear late or across multiple inventory pages.
    • Added safeguards for incomplete, duplicated, inconsistent, or oversized workflow-run listings.
    • Improved handling of stale and zero-match dispatch receipts, including replacement checks.
    • Standardized validation of GitHub request identifiers.
    • Improved consistency of PR gate status titles during evaluation, authorization, and retry flows.
  • Tests

    • Expanded end-to-end coverage for paginated inventory and delayed workflow-run scenarios.

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
@coderabbitai

coderabbitai Bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Dispatch reconciliation now supports paginated workflow-run inventory validation and expanded stale-receipt tests. GitHub request ID validation and reconciliation limits are shared across modules, while PR-gate expected titles are centralized into constants and helpers.

Changes

Dispatch reconciliation

Layer / File(s) Summary
Receipt validation and reconciliation limits
tools/advisors/github.mts, tools/e2e/pr-e2e-retry-receipt.mts, tools/e2e/pr-e2e-dispatch-reconciliation.mts
GitHub request ID validation is centralized, the reconciliation window cap is exported, and receipt validation uses the shared type guard.
Paginated workflow inventory rechecks
tools/e2e/pr-e2e-dispatch-reconciliation.mts
Workflow-run inventory reads aggregate validated pages, reject unstable or duplicate listings, enforce limits, and support stale-dispatch replacement checks.
Reconciliation scenario coverage
test/pr-e2e-dispatch-reconciliation.test.ts
Tests cover old zero-match receipts, pagination, late correlations, inconsistent listings, duplicate runs, and filtered-result caps.

PR-gate title consistency

Layer / File(s) Summary
Expected gate title construction
tools/e2e/pr-e2e-gate.mts
Pre-dispatch validation, runner-loss retries, and authorized execution use centralized expected-title constants and a title-construction helper.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant assertDispatchStillNotObserved
  participant readPaginatedInventory
  participant GitHubWorkflowRunsAPI
  assertDispatchStillNotObserved->>readPaginatedInventory: recheck stale receipt
  readPaginatedInventory->>GitHubWorkflowRunsAPI: request workflow-run inventory page
  GitHubWorkflowRunsAPI-->>readPaginatedInventory: return paginated workflow runs
  readPaginatedInventory-->>assertDispatchStillNotObserved: return validated inventory
Loading

Possibly related issues

Possibly related PRs

Suggested labels: area: ci, area: e2e

Suggested reviewers: cv, prekshivyas

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: paginating stale dispatch receipt rechecks.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/7593-stale-receipt-pagination

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall coverage in commit 0693c16 in the codex/7593-stale-rec... branch remains at 96%, unchanged from commit f7d2531 in the main branch.

TypeScript / code-coverage/cli

The overall coverage in commit 0693c16 in the codex/7593-stale-rec... branch remains at 80%, unchanged from commit f7d2531 in the main branch.

Show a code coverage summary of the most impacted files.
File main f7d2531 codex/7593-stale-rec... 0693c16 +/-
src/lib/onboard...box-prebuild.ts 92% 73% -19%
src/lib/actions...ocker-health.ts 82% 65% -17%
src/lib/actions...confirmation.ts 79% 69% -10%
src/lib/onboard...box-gpu-mode.ts 97% 92% -5%
src/lib/actions...light-guards.ts 90% 86% -4%
src/lib/onboard/preflight.ts 80% 80% 0%
src/lib/actions...eway-restart.ts 94% 95% +1%
src/lib/onboard...host-anchors.ts 90% 94% +4%
src/lib/shields/index.ts 67% 72% +5%
src/lib/onboard/docker-cdi.ts 70% 80% +10%

Updated July 26, 2026 20:51 UTC

@github-actions

github-actions Bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — No blocking findings reported

Advisor assessment: No blocking advisor findings reported
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions

Model lanes

  • GPT-5.6 Terra (primary): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Nemotron 3 Ultra (second opinion): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Model comparison: normalized findings match; normalized E2E selections differ; severity counts match.

Nemotron output stays in workflow artifacts and does not change the assessment above.

E2E guidance

Advisory only. E2E / PR Gate selects and runs jobs independently.

Recommended E2E: cloud-onboard, credential-sanitization, security-posture

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
test/pr-e2e-dispatch-reconciliation.test.ts (1)

415-486: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick win

Add a success test at the pagination cap boundary.

Coverage proves the cap rejects total_count = 1_001 (one over the limit) but nothing proves a total_count exactly at MAX_WORKFLOW_RUNS * MAX_WORKFLOW_RUN_PAGES (10 full pages) still succeeds. That's the case most exposed to an off-by-one regression in the loop's page <= MAX_WORKFLOW_RUN_PAGES bound.

✅ Suggested boundary test
it("succeeds when a stale receipt inventory exactly fills the page cap", async () => {
  const runs = Array.from({ length: 1_000 }, (_value, index) => unrelatedWorkflowRun(index + 100));
  const api = paginatedInventoryApi(runs);

  await expect(
    assertDispatchStillNotObserved(oldReceiptOptions(), {
      api,
      now: () => SENT_AT_MS + WINDOW_MS + 2_000,
      clockSkewMs: 10,
    }),
  ).resolves.toBeUndefined();
  expect(api).toHaveBeenCalledTimes(10);
});
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/pr-e2e-dispatch-reconciliation.test.ts` around lines 415 - 486, Add a
success test alongside the existing pagination tests covering exactly 1,000
inventory runs, representing MAX_WORKFLOW_RUNS * MAX_WORKFLOW_PAGES. Use
paginatedInventoryApi with assertDispatchStillNotObserved and verify it resolves
successfully after exactly 10 API calls, preserving coverage of the inclusive
pagination cap boundary.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@test/pr-e2e-dispatch-reconciliation.test.ts`:
- Around line 415-486: Add a success test alongside the existing pagination
tests covering exactly 1,000 inventory runs, representing MAX_WORKFLOW_RUNS *
MAX_WORKFLOW_PAGES. Use paginatedInventoryApi with
assertDispatchStillNotObserved and verify it resolves successfully after exactly
10 API calls, preserving coverage of the inclusive pagination cap boundary.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: df6687e0-2f9b-46ac-b34e-e329f88f6af5

📥 Commits

Reviewing files that changed from the base of the PR and between f7d2531 and 0693c16.

📒 Files selected for processing (5)
  • test/pr-e2e-dispatch-reconciliation.test.ts
  • tools/advisors/github.mts
  • tools/e2e/pr-e2e-dispatch-reconciliation.mts
  • tools/e2e/pr-e2e-gate.mts
  • tools/e2e/pr-e2e-retry-receipt.mts

@cv
cv merged commit cb160ea into main Jul 26, 2026
75 of 78 checks passed
@cv
cv deleted the codex/7593-stale-receipt-pagination branch July 26, 2026 20:58
cv pushed a commit that referenced this pull request Jul 26, 2026
<!-- markdownlint-disable MD041 -->
## Summary

Add the exact upper-bound regression requested during review of #7595. A complete stale-receipt inventory containing 1,000 workflow runs across all 10 allowed pages must remain retryable rather than failing from an off-by-one pagination error.

## Related Issue

Follow-up to #7595 and #7594 for #7593.
Part of #7140.

## Changes

- Exercise the inclusive 1,000-run filtered-search cap.
- Require the receipt recheck to consume exactly 10 complete pages.
- Preserve the existing zero-correlation success contract at the boundary.

## Type of Change

- [x] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [ ] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [x] Tests added or updated for changed behavior
- [ ] Existing tests cover changed behavior — justification:
- [ ] Tests not applicable — justification:
- [ ] Docs updated for user-facing behavior changes
- [x] Docs not applicable — justification: this is a test-only boundary follow-up with no runtime or user-facing behavior change.
- [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
- [x] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: Exact product-scope and nine-category security review PASS at `871b933840300068aef3f462a8ecf1d0873209dc` (tree `4e2d18d2833a353776d6936fd22d28f3c95ad2d9`, base `17a8ad1a6979de0b92b25eb93453dbbdf03cf61a`). The diff is test-only; it exercises the exact fail-closed pagination boundary and changes no production code, dependency, permission, credential path, or supported product surface.
- [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

## Documentation Writer Review

- [x] Documentation writer subagent reviewed the completed changes
- Result: `no-docs-needed`
- Evidence: Test-only regression coverage for the existing GitHub filtered-result pagination cap; no user-visible behavior changed and #7594's operational guidance remains accurate.
- Agent: Codex Desktop
<!-- docs-review-head-sha: 871b933 -->
<!-- docs-review-agents-blob-sha: be20a09 -->

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit:
- Station profile/scenario:
- Result:
- Supporting evidence:

## Verification

- [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — exact head `871b933840300068aef3f462a8ecf1d0873209dc`: `npx vitest run --project integration test/pr-e2e-dispatch-reconciliation.test.ts` passed 35/35.
- [x] Applicable broad gate passed — CLI build and exact-head `npm run check:diff` passed after generating the required `dist/` artifacts.
- [x] Quality Gates section completed with required justifications or waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only)
- [ ] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

---
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **Tests**
  * Added end-to-end coverage for reconciling complete stale receipt inventories at GitHub’s filtered-result limit.
  * Verified reconciliation succeeds with clock skew and across paginated inventory reads, including the page-cap boundary (ensuring calls span the expected pages).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@cv cv mentioned this pull request Jul 26, 2026
23 tasks
apurvvkumaria pushed a commit that referenced this pull request Jul 27, 2026
<!-- markdownlint-disable MD041 -->
## Summary

Add the canonical `docs/changelog/2026-07-25.mdx` release entry with the
exact `## v0.0.96` heading.
The entry reconciles all 90 first-parent commits since v0.0.95 with all
92 merged PRs in the live `v0.0.96` label ledger and groups the
user-visible changes by operator journey.

## Changes

- Add the parser-safe dated MDX changelog entry for v0.0.96 with
root-absolute links to the focused user guides.
- Source summary:
- [#7194](#7194) ->
`docs/changelog/2026-07-25.mdx`: Document persistent baseline network
policy exclusions and their inspection, rebuild, and snapshot behavior.
- [#7188](#7188),
[#7427](#7427), and
[#7546](#7546) ->
`docs/changelog/2026-07-25.mdx`: Document DNS-backed HTTPS inference
routing, keyless loopback endpoints, and provider-marker isolation.
- [#7238](#7238) ->
`docs/changelog/2026-07-25.mdx`: Document blueprint sandbox and provider
identifier validation before state writes or OpenShell calls, with
bounded terminal-safe rejection previews.
- [#7319](#7319),
[#7274](#7274),
[#7528](#7528),
[#7353](#7353), and
[#7560](#7560) ->
`docs/changelog/2026-07-25.mdx`: Document the managed default gateway
service, onboarding readiness, and container-runtime identity
safeguards.
- [#7349](#7349),
[#7498](#7498),
[#7406](#7406),
[#7196](#7196),
[#7559](#7559),
[#7421](#7421),
[#7510](#7510),
[#7295](#7295), and
[#7565](#7565) ->
`docs/changelog/2026-07-25.mdx`: Document gateway-scoped status,
lifecycle diagnostics, managed MCP recovery, delete-edge safeguards, and
fail-closed CLI prompt and command output.
- [#7591](#7591) ->
`docs/changelog/2026-07-25.mdx`: Document opt-in authenticated MCP
tool-name discovery, its bounded and names-only contract, probe
interaction, and rebuild requirement.
- [#7305](#7305),
[#7480](#7480),
[#7471](#7471),
[#7365](#7365), and
[#7541](#7541) ->
`docs/changelog/2026-07-25.mdx`: Document installer version checks,
version-tag reporting, license guidance, WSL Ollama selection, and DGX
Station vLLM detection.
- [#7482](#7482),
[#7466](#7466),
[#7208](#7208),
[#7434](#7434), and
[#7586](#7586) ->
`docs/changelog/2026-07-25.mdx`: Document Ollama resource details,
reasoning precedence, Hermes onboarding behavior, and preserved managed
Hermes BuildKit failures.

- [#6830](#6830),
[#7492](#7492),
[#7563](#7563), and
[#7582](#7582) ->
`docs/changelog/2026-07-25.mdx`: Document the authoritative OpenClaw
production lock, fixed managed-image dependencies, immutable Hermes base
adoption, and Hermes image-size reduction.
- [#7505](#7505),
[#7530](#7530),
[#7547](#7547),
[#7508](#7508),
[#7548](#7548),
[#7549](#7549),
[#7537](#7537),
[#7534](#7534),
[#7515](#7515),
[#7511](#7511),
[#7551](#7551),
[#7562](#7562),
[#7575](#7575),
[#7496](#7496),
[#7594](#7594),
[#7595](#7595), and
[#7599](#7599) ->
`docs/changelog/2026-07-25.mdx`: Summarize release validation, transient
and bounded dispatch reconciliation, exact pre-tag qualification,
identity revalidation, npm-audit retry, sharding, image reuse, timeout,
telemetry, and workflow-hardening changes.
- Reconciled without separate changelog prose:
- [#7539](#7539),
[#7526](#7526),
[#7507](#7507),
[#7506](#7506),
[#7519](#7519),
[#7516](#7516),
[#7396](#7396),
[#7254](#7254),
[#7583](#7583),
[#7596](#7596), and
[#7598](#7598): Test-harness or
fixture-only changes.
- [#7403](#7403),
[#7161](#7161),
[#6877](#6877),
[#7531](#7531),
[#7525](#7525),
[#7522](#7522),
[#7536](#7536),
[#7552](#7552),
[#7566](#7566),
[#7553](#7553),
[#7561](#7561),
[#7577](#7577),
[#7569](#7569),
[#7585](#7585),
[#7584](#7584),
[#7592](#7592),
[#7580](#7580),
[#7571](#7571),
[#7517](#7517),
[#7589](#7589),
[#7402](#7402),
[#7558](#7558),
[#7544](#7544), and
[#7601](#7601): Dependency,
internal recovery, validation, contributor-workflow, E2E optimization,
telemetry, or CI trust changes with no separate user-facing release
claim.
- [#7556](#7556),
[#7573](#7573),
[#7576](#7576), and
[#7578](#7578): Experimental
repository-maintainer conflict automation with no canonical user
documentation surface.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [x] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [ ] Tests added or updated for changed behavior
- [x] Existing tests cover changed behavior — justification:
`test/changelog-docs.test.ts` validates dated changelog structure,
version headings, and published links.
- [ ] Tests not applicable — justification:
- [x] Docs updated for user-facing behavior changes
- [ ] Docs not applicable — justification:
- [ ] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [ ] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification:
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## Documentation Writer Review

- [x] Documentation writer subagent reviewed the completed changes
- Result: `docs-updated`
- Evidence: Reviewed `docs/changelog/2026-07-25.mdx` at exact head
`0f5dedb47` against 90 first-parent release commits and 92 merged PRs
labeled `v0.0.96`. Verified parser-safe MDX SPDX, the exact version
heading, literal CLI names, writing style, skip terms, all 20
root-absolute published links, and the accepted #7591 opt-in
authenticated discovery bounds. #7544, #7599, and #7601 remain internal
or CI-only release-ledger entries. Changelog tests passed 6/6, the docs
build passed with 0 errors and two pre-existing Fern warnings, and `npm
run check:diff` plus the final diff check passed.
- Agent: Codex Desktop documentation-writer subagent
<!-- docs-review-head-sha: 0f5dedb -->
<!-- docs-review-agents-blob-sha: be20a09 -->

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit:
- Station profile/scenario:
- Result:
- Supporting evidence:

## Verification

- [x] PR description includes a `Signed-off-by:` line and every commit
appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or
`npm run check:diff` passed when hooks were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests
are marked not applicable above — `npx vitest run
test/changelog-docs.test.ts`: 6/6 passed.
- [ ] Applicable broad gate passed — `npm test` for broad
runtime/test-harness changes; `npm run check` for repo-wide
validation/coverage changes — command/result: Not applicable to this
prose-only changelog entry.
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only) — the
build passed with 0 errors and 2 existing Fern warnings; the
published-route check passed.
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)
— native changelog files use the required parser-safe MDX SPDX comment
and no frontmatter.

---
Signed-off-by: Carlos Villela <cvillela@nvidia.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Persistent network policy exclusions with consistent restore/exclusion
reporting across rebuilds/snapshots.
* Opt-in MCP tool discovery via `mcp status --tools` with bounded,
redacted authenticated traffic.
* Improved HTTPS inference switching for custom endpoints and refreshed
onboarding/model menu details.
* Refined OpenShell gateway defaults for port `8080`, including more
reliable readiness checks.
* **Bug Fixes**
* Prevent incorrect provider/model restoration after compatible-provider
update failures.
* Preserve managed MCP state after exec loss and tighten gateway/doctor
status scoping.
* **Tests**
* Stronger, fail-closed release validation with hardened
evidence/artifact handoff and bounded timeouts/retries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Co-authored-by: Prekshi Vyas <prekshiv@nvidia.com>
@wscurran wscurran added area: ci CI workflows, checks, release automation, or GitHub Actions area: e2e End-to-end tests, nightly failures, or validation infrastructure bug-fix PR fixes a bug or regression labels Jul 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci CI workflows, checks, release automation, or GitHub Actions area: e2e End-to-end tests, nightly failures, or validation infrastructure bug-fix PR fixes a bug or regression

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants