Repository navigation
chore(deps): trust OpenClaw 2026.9.5 manifests - #12380
nvidia-nemopatch-writer[bot] wants to merge 15 commits into
Conversation
Patch-Walker-Manifest: sha256:8f02f4a58b35b10021a74ce9c687302a9955962b722a1eab2dd2cb2085b638a3 Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall line coverage in commit 12b1ae6 in the Show a line coverage summary of the most impacted files.
TypeScript / code-coverage/cliThe overall line coverage in commit 12b1ae6 in the Show a line coverage summary of the most impacted files.
Updated |
Patch-Walker-Manifest: sha256:0bc3b7783ef39fb636ddaff4a2769d9a18b29140fa835bfbdbef18d32be4285a Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a NemoPatch-Draft-Rebase: sha256:cc14a16725fe524469e3772b77626e607b690c4c239197456dfd2ee18807104e Previous-Head: 149296d Previous-Base: 3f98fc7 Previous-Action-Base: 241fcd1 Base-Commit: 4355902 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:aefb923570aafcfac1dbcdf63668265d81ce9b7edbc337468c1e7deb9ca18ff8 Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a NemoPatch-Draft-Rebase: sha256:89cafad604a83e50b8537d3d3355d9300cb54e11f632f0ac50d732cbf730f9dc Previous-Head: 9972df9 Previous-Base: 3f98fc7 Previous-Action-Base: 4355902 Base-Commit: 7e1310c Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
@coderabbitai review |
|
@coderabbitai review |
|
@coderabbitai review |
|
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Integrate the upstream SDK 1.31.0 repair and compaction safeguard. Reconcile reviewed locks, offline archives, bundle assertions and fixtures. Bind the replacement-lock fixture to the reviewed OpenClaw 9.5 graph. User-approved Pi receipt deferral applies only to this bootstrap publication. Genuine AMD64 and ARM64 qualification and the full gate remain required. Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
PR Review Advisor finished for commit Request review only when Require no Advisor blockers is green. |
Outcome
Adds reviewed OpenClaw 2026.9.5 archive and replacement-graph identities while preserving the selected 2026.9.2 runtime and its existing trust entries.
Reason
The runtime migration in #12382 needs verified package identities and a reviewed replacement graph before selecting 2026.9.5. This PR stages that policy without changing the production runtime.
Changes
Verification
12b1ae63f10dbbbe17207ea059c4a9df16f048b9. It includes main’s MCP SDK security repair, corrected archive inputs, and genuine source-matching AMD64/ARM64 Pi receipts from run 37520336741, attempt 1.12b1ae63f10dbbbe17207ea059c4a9df16f048b9, with empty selectors and the authorized Brev Launchable lane. Its authenticated dispatch receipt records base24a38a6bd34474247b2cfe55112d149dbb483ea4and trusted workflow2306bc5f49c7a2f2697e9dfc781b5f4d21dc3580. The run has 76 successful jobs, four failed leaf jobs plus the failed aggregate, and 13 skipped jobs. Failed lanes: Deep Agents repository onboarding, OpenClaw inference-switch, protected GPU qualification, and Brev Launchable. The first two have matching failures on main and unchanged relevant source; their complete current-run audits remain in progress. The protected job failed before runtime startup: the trusted controller accepts OpenClaw lock SHA-256b44c7f475fe36a378ebc078dbf068bd225f8470002834ce1308872049213b633, while this candidate containsa577575ac9d6821fe5b75b896de2ec4dc1661ce0da369b86666c0ebe6fec19d6. The trusted identity selector reproduces this rejection locally. Main’s fix(inference): use completion token limits for GPT-6 probes #12691 updated the SDK requested-version metadata; this candidate needs that dependency before another qualification run. No audit policy was weakened or rerun dispatched. The Launchable producer succeeded and exact candidate boot provenance passed. Its full test failed atfull-e2e.test.ts:284: the gateway restart after native plugin installation returned a health timeout. Sandbox cleanup and final Brev workspace absence were verified. Relevant source is unchanged from the PR base, but available main Launchable runs failed during image production and cannot establish a matching runtime failure. The cause and relevance remain under review; this is not a passing full qualification.Review notes
Self-review covered archive identities, replacement lock provenance, genuine Pi receipt parity, and the documentation boundary. The existing candidate-owned audit design was adopted by merged PR #12507; this upgrade does not change that ownership. The current Advisor result is clear. Independent approval and successful final live qualification remain pending.
This remains a draft. CodeRabbit is deferred at the user's direction; no merge is authorized.
Signed-off-by: Prekshi Vyas prekshiv@nvidia.com