Skip to content

chore(deps): trust OpenClaw 2026.9.5 manifests - #12380

Draft
nvidia-nemopatch-writer[bot] wants to merge 15 commits into
mainfrom
nemopatch/openclaw-upgrade/ddb54e135216a516/trust
Draft

nvidia-nemopatch-writer[bot] wants to merge 15 commits into
mainfrom
nemopatch/openclaw-upgrade/ddb54e135216a516/trust

Conversation

@nvidia-nemopatch-writer

@nvidia-nemopatch-writer nvidia-nemopatch-writer Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Outcome

Adds reviewed OpenClaw 2026.9.5 archive and replacement-graph identities while preserving the selected 2026.9.2 runtime and its existing trust entries.

Reason

The runtime migration in #12382 needs verified package identities and a reviewed replacement graph before selecting 2026.9.5. This PR stages that policy without changing the production runtime.

Changes

  • Preserve current runtime identities and security overrides; add the 2026.9.5 runtime, official channels (including Google Chat), Brave, Tavily, and diagnostics archives.
  • Bind the replacement runtime graph to the actual 2026.9.5 lockfile digest and exercise the checked-in policy with that lock fixture.
  • Document the staged transition, its removal condition, and the existing candidate-owned audit boundary accurately.
  • Refresh genuine AMD64/ARM64 Pi qualification receipts and their exact authority hashes from run 37520336741, attempt 1. The full receipt gate verifies matching image inputs.

Verification

  • Current candidate: 12b1ae63f10dbbbe17207ea059c4a9df16f048b9. It includes main’s MCP SDK security repair, corrected archive inputs, and genuine source-matching AMD64/ARM64 Pi receipts from run 37520336741, attempt 1.
  • Full normal signed-commit and publication hooks passed, including CLI typecheck and the Pi receipt gate. GitHub verifies the published signature. No secrets, API keys, or credentials were added.
  • Current CI passed, including the real OpenClaw distribution tests and npm audits.
  • Current Advisor passed. All nine complete specialist reports were collected and reviewed; there are no blocking findings.
  • Managed-image evaluation, attempt 2 passed. The authorized single Docker activation retry completed all three managed agents, 28 native agent turns, stop/start and durable-state checks, exact public-image adoption/rebuild, and cleanup with no failures. The authenticated artifact binds the runtime result to this exact candidate. The original Hermes image-download failure remains retained as historical attempt-1 evidence.
  • Full trusted manual E2E run 37564477057 completed with failure for 12b1ae63f10dbbbe17207ea059c4a9df16f048b9, with empty selectors and the authorized Brev Launchable lane. Its authenticated dispatch receipt records base 24a38a6bd34474247b2cfe55112d149dbb483ea4 and trusted workflow 2306bc5f49c7a2f2697e9dfc781b5f4d21dc3580. The run has 76 successful jobs, four failed leaf jobs plus the failed aggregate, and 13 skipped jobs. Failed lanes: Deep Agents repository onboarding, OpenClaw inference-switch, protected GPU qualification, and Brev Launchable. The first two have matching failures on main and unchanged relevant source; their complete current-run audits remain in progress. The protected job failed before runtime startup: the trusted controller accepts OpenClaw lock SHA-256 b44c7f475fe36a378ebc078dbf068bd225f8470002834ce1308872049213b633, while this candidate contains a577575ac9d6821fe5b75b896de2ec4dc1661ce0da369b86666c0ebe6fec19d6. The trusted identity selector reproduces this rejection locally. Main’s fix(inference): use completion token limits for GPT-6 probes #12691 updated the SDK requested-version metadata; this candidate needs that dependency before another qualification run. No audit policy was weakened or rerun dispatched. The Launchable producer succeeded and exact candidate boot provenance passed. Its full test failed at full-e2e.test.ts:284: the gateway restart after native plugin installation returned a health timeout. Sandbox cleanup and final Brev workspace absence were verified. Relevant source is unchanged from the PR base, but available main Launchable runs failed during image production and cannot establish a matching runtime failure. The cause and relevance remain under review; this is not a passing full qualification.

Review notes

Self-review covered archive identities, replacement lock provenance, genuine Pi receipt parity, and the documentation boundary. The existing candidate-owned audit design was adopted by merged PR #12507; this upgrade does not change that ownership. The current Advisor result is clear. Independent approval and successful final live qualification remain pending.

This remains a draft. CodeRabbit is deferred at the user's direction; no merge is authorized.


Signed-off-by: Prekshi Vyas prekshiv@nvidia.com

Patch-Walker-Manifest: sha256:8f02f4a58b35b10021a74ce9c687302a9955962b722a1eab2dd2cb2085b638a3
Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b35aa805-9f96-409d-96c0-ad70dc09f0b8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 12b1ae6 in the nemopatch/openclaw-u... branch is 97%. The line coverage in commit 63002cd in the main branch is 96%.

Show a line coverage summary of the most impacted files.
File main 63002cd nemopatch/openclaw-u... 12b1ae6 +/-
nemoclaw/src/onboard/config.ts 98% 96% -2%
nemoclaw/src/index.ts 94% 93% -1%
nemoclaw/src/bl...t-management.ts 100% 100% 0%
nemoclaw/src/co.../config-show.ts 100% 100% 0%
nemoclaw/src/commands/slash.ts 100% 100% 0%
nemoclaw/src/on...native-route.ts 0% 100% +100%

TypeScript / code-coverage/cli

The overall line coverage in commit 12b1ae6 in the nemopatch/openclaw-u... branch is 85%. The line coverage in commit 63002cd in the main branch is 84%.

Show a line coverage summary of the most impacted files.
File main 63002cd nemopatch/openclaw-u... 12b1ae6 +/-
src/lib/state/s...tory-restore.ts 86% 0% -86%
src/lib/actions.../status-text.ts 84% 46% -38%
src/lib/state/sandbox.ts 92% 83% -9%
src/lib/onboard...al-inference.ts 84% 90% +6%
src/lib/policy/index.ts 71% 79% +8%
src/lib/state/p...l-retirement.ts 79% 92% +13%
src/lib/onboard.../application.ts 55% 72% +17%
src/lib/adapter...gnostics-cli.ts 0% 87% +87%
src/lib/onboard...ternal-image.ts 0% 94% +94%
src/lib/securit...ig-structure.ts 0% 98% +98%

Updated October 06, 2026 20:46 UTC

Patch-Walker-Manifest: sha256:0bc3b7783ef39fb636ddaff4a2769d9a18b29140fa835bfbdbef18d32be4285a
Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a
NemoPatch-Draft-Rebase: sha256:cc14a16725fe524469e3772b77626e607b690c4c239197456dfd2ee18807104e
Previous-Head: 149296d
Previous-Base: 3f98fc7
Previous-Action-Base: 241fcd1
Base-Commit: 4355902

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
nvidia-nemopatch-writer Bot pushed a commit that referenced this pull request Sep 28, 2026
Patch-Walker-Manifest: sha256:7b61075f19f9cce050ec27dd0dda884489d46621b635f33fd2950fb2428110c2
Prerequisite-PR: #12380
Prerequisite-Commit: 9972df9

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:aefb923570aafcfac1dbcdf63668265d81ce9b7edbc337468c1e7deb9ca18ff8
Patch-Walker-Action: sha256:3d286db0269406f5d7f4ca1498088b786bfdbdfcb2b7a5c5b7160f9284b9dd2a
NemoPatch-Draft-Rebase: sha256:89cafad604a83e50b8537d3d3355d9300cb54e11f632f0ac50d732cbf730f9dc
Previous-Head: 9972df9
Previous-Base: 3f98fc7
Previous-Action-Base: 4355902
Base-Commit: 7e1310c

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
nvidia-nemopatch-writer Bot pushed a commit that referenced this pull request Sep 28, 2026
Patch-Walker-Manifest: sha256:4d7c1202834c4b68005ef21c866cfa0784f84eb1cde75f1adfad993a2d43aae3
Prerequisite-PR: #12380
Prerequisite-Commit: 4603d1d

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@prekshivyas
prekshivyas marked this pull request as ready for review September 29, 2026 02:25
@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@prekshivyas
prekshivyas marked this pull request as draft September 29, 2026 05:56
@prekshivyas

Copy link
Copy Markdown
Collaborator

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review skipped.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@wscurran wscurran added area: packaging Packages, images, registries, installers, or distribution area: security Security controls, permissions, secrets, or hardening integration: brave Brave integration behavior integration: discord Discord integration or channel behavior integration: openclaw OpenClaw integration behavior integration: slack Slack integration or channel behavior integration: whatsapp WhatsApp integration or channel behavior labels Oct 6, 2026
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Integrate the upstream SDK 1.31.0 repair and compaction safeguard.
Reconcile reviewed locks, offline archives, bundle assertions and fixtures.
Bind the replacement-lock fixture to the reviewed OpenClaw 9.5 graph.

User-approved Pi receipt deferral applies only to this bootstrap publication.
Genuine AMD64 and ARM64 qualification and the full gate remain required.

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor finished for commit 12b1ae6. Include the Advisor findings in the complete PR feedback collection. Verify and group valid findings before repair.

Request review only when Require no Advisor blockers is green.

All previous runs

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: packaging Packages, images, registries, installers, or distribution area: security Security controls, permissions, secrets, or hardening integration: brave Brave integration behavior integration: discord Discord integration or channel behavior integration: openclaw OpenClaw integration behavior integration: slack Slack integration or channel behavior integration: whatsapp WhatsApp integration or channel behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants