fix(onboard): keep unprovable forward ports occupied instead of failing allocation - #12352
sandeepstele wants to merge 1 commit into
Conversation
…ng allocation One indeterminate forward-ownership observation made the dashboard and Hermes API allocators throw before scanning, so a single port NemoClaw could not verify (for example one held by another user's process) blocked every free port in the range. Throw only when an observation failed for a reason other than ownership. A port whose ownership cannot be proven stays occupied, as the allocator's contract already states, and the scan continues. When no port can be verified, the range-exhausted error names each unverified port. Refs NVIDIA#11979 Signed-off-by: Sandeep Satheesh <sandeep.sath7@gmail.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe allocator now skips ownership-indeterminate observations during its early failure check. Tests cover selecting the next absent port and retaining failures for exhausted ranges and timeout observations. ChangesPort Allocation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The allocator can now try later free ports without claiming ports whose ownership is uncertain, while other indeterminate results still stop allocation. No material merge-blocking risk is evident. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@rsliter Thanks for #12484. It builds on the #11963 measurements and cuts the dashboard scan to one authority check per batch. This PR complements it. #12484 makes the observation fast. This one keeps a single port whose ownership cannot be proven from blocking the whole range: the port is treated as occupied, and allocation continues. That is the #11979 case, where another user's listener is invisible to non-root I checked it against current When you have a moment, could a vetter run |
Outcome
A dashboard or Hermes API port whose OpenShell forward ownership cannot be proven is now treated as occupied, and allocation moves on to the next port. Before this change, one such port made allocation fail with
Cannot allocate dashboard port: NemoClaw could not prove OpenShell forward ownership., even when free ports remained in the range. Observations that fail for any other reason (timeout, transport, command, validation) still stop allocation.Reason
findAvailablePortInRangeFromObservationsthrew on the firstindeterminateobservation, before scanning the range. Its own contract says: "Foreign, indeterminate, and missing observations stay occupied so allocation never converts uncertainty into permission to bind."observedForwardPortAvailabilityalready maps such a port toblocked, which the allocator records as "unverified OpenShell forward ownership".In #11979, on a shared host, a listener that belongs to another user is invisible to non-root
lsofbut reachable, so the adapter reports that one port as ownership-indeterminate. That port then blocks the whole dashboard range, and the Hermes API port range has the same problem.Related issues
Refs #11979. This fixes the allocator side. If a host's
lsofmakes every port unverifiable, for example through stderr warnings, onboarding still stops. It now does so with the range-exhausted error that lists each unverified port, instead of a single opaque ownership message. Adapter-side detection is unchanged.Changes
src/lib/onboard/dashboard-port.ts: throw only for anindeterminateobservation whose error kind is notownership. Ownership-indeterminate ports keep their existingblocked→ occupied handling. The Hermes API allocator (hermes-api-port.ts) uses the same function, so it gets the same fix.src/lib/onboard/dashboard-port.test.ts:timeoutobservation still stops allocation.src/lib/onboard/hermes-api-port.test.ts: the matching Hermes test now expects the next free port.Verification
npx vitest run src/lib/onboard/dashboard-port.test.ts src/lib/onboard/hermes-api-port.test.ts: 79 passed. Withmain'sdashboard-port.ts, the three new or updated expectations fail.npx vitest run src/lib/onboard/: 565 files, 9529 passed, 1 skipped.npm run typecheck:cli: passed.Review notes
src/lib/onboard/**. No independent pre-publication review exists. The author self-reviewed the change and checked the tests againstmain's allocator, so it is awaiting maintainer review.port === preferredPortguard is a small follow-up.openshell-sdk-packagefails with "The reviewed SDK is available only to same-repository pull requests".Signed-off-by: Sandeep Satheesh sandeep.sath7@gmail.com
Summary by CodeRabbit