Skip to content

fix(onboard): reduce dashboard forward authority checks - #12484

Merged
prekshivyas merged 1 commit into
mainfrom
codex/11963-forward-fence
Sep 29, 2026
Merged

prekshivyas merged 1 commit into
mainfrom
codex/11963-forward-fence

Conversation

@rsliter

@rsliter rsliter commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Outcome

Dashboard forward observation now performs one gateway authority check for each valid read-only multi-port batch instead of repeating synchronous ownership checks for every unbound port. The final fence rejects the complete batch if gateway authority is stale or changes during observation.

Reason

On macOS with a Homebrew-managed gateway, the 11-port dashboard scan performed 27 synchronous formula identity operations and consumed about 32.6 seconds, exceeding the 15-second observation budget.

Related issues

Refs #11963

Changes

  • Keep strict adapter-level authority fencing unchanged for mutation, startup, retirement, and recovery consumers.
  • Validate the adapter response count and exact forward identities before running one final gateway authority fence for the read-only dashboard observation batch.
  • Protect the behavior with regressions for one fence per multi-port batch, fresh fencing across independent batches, stale or changed authority denial, and malformed identity rejection before the external authority check.

Verification

  • NODE_OPTIONS=--max-old-space-size=8192 npm run validate:pr passed repository checks, secret scanning, CLI and plugin builds, publication validation, and CLI TypeScript checks.
  • npx vitest run --project cli src/lib/onboard/dashboard-port.test.ts src/lib/adapters/openshell/forward-cli.test.ts passed 123 tests in 2 files.
  • npx vitest run --project integration test/automation/pull-requests/growth-guardrails.test.ts passed 7 tests.
  • Secrets review: The diff contains no secrets, API keys, or credentials.

Review notes

  • Sensitive-path review: exact candidate 1627a326478679c0c195c8b203e219c406a69aa4 changes src/lib/onboard/dashboard-port.ts and its focused test. The coordinating agent independently reviewed the measured root cause, sibling forward-allocation paths, and wrapper-only final-fence design before commit. The exact final candidate also received local self-review. Automated and independent human review remain pending.
  • Scope: this directly addresses the measured macOS Homebrew authority-check timeout. WSL and cloud manifestations still require live retest, so this PR references rather than closes [macOS/WSL2][Onboard][Regression] OpenShell dashboard forward times out and blocks sandbox onboarding #11963.

Signed-off-by: Rebecca Sliter 571084+rsliter@users.noreply.github.com

Summary by CodeRabbit

  • Bug Fixes
    • Improved the reliability of dashboard port observations. Results are now rejected if gateway authority is no longer current when collection completes, and each new batch receives a fresh authority check.
    • Invalid responses are rejected before gateway authority is checked.

Signed-off-by: Rebecca Sliter <571084+rsliter@users.noreply.github.com>
@rsliter rsliter self-assigned this Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: NVIDIA/NemoClaw/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 59d69369-48ad-4339-925e-cdc320872fbc

📥 Commits

Reviewing files that changed from the base of the PR and between f1b5a6b and 1627a32.

📒 Files selected for processing (2)
  • src/lib/onboard/dashboard-port.test.ts
  • src/lib/onboard/dashboard-port.ts

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.


📝 Walkthrough

Walkthrough

The dashboard forward observer now checks authority once after it receives and validates the adapter’s observations. The tests cover stale authority before and during collection, fresh checks on subsequent batches, and mismatched-identity responses.

Changes

Dashboard forward authority check

Layer / File(s) Summary
Validate observations and check authority
src/lib/onboard/dashboard-port.ts, src/lib/onboard/dashboard-port.test.ts
The observer no longer passes assertCurrent to the adapter. It checks authority after response validation and before returning observations. Tests verify one check per batch, rejection when authority is stale, and no check for a mismatched-identity response.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: cv

Merge Risk: ⚪ Minimal · up to 1627a

The change reduces repeated authority checks during dashboard forward observation, which addresses the reported onboarding timeout on macOS. No merge-blocking risk was found. WSL and cloud cases still need live retesting, as the author notes.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: reducing dashboard forward authority checks during onboarding.
Linked Issues check ✅ Passed The changes address the coding scope of issue #11963. createOpenShellForwardPortObserver now collects a valid multi-port batch without per-forward authority fencing, validates response count and exa…
Out of Scope Changes check ✅ Passed The reviewed changes are limited to dashboard-port observation and its tests. They modify authority-check timing and evidence validation for read-only dashboard-forward allocation. The tests support t…
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall line coverage in commit 1627a32 in the codex/11963-forward-... branch remains at 96%, unchanged from commit 63002cd in the main branch.

Show a line coverage summary of the most impacted files.
File main 63002cd codex/11963-forward-... 1627a32 +/-
nemoclaw/src/onboard/config.ts 98% 96% -2%
nemoclaw/src/index.ts 94% 93% -1%
nemoclaw/src/co.../config-show.ts 100% 100% 0%
nemoclaw/src/commands/slash.ts 100% 100% 0%
nemoclaw/src/on...native-route.ts 0% 100% +100%

TypeScript / code-coverage/cli

The overall line coverage in commit 1627a32 in the codex/11963-forward-... branch is 85%. The line coverage in commit 63002cd in the main branch is 84%.

Show a line coverage summary of the most impacted files.
File main 63002cd codex/11963-forward-... 1627a32 +/-
src/lib/actions.../status-text.ts 84% 46% -38%
src/lib/inferen...er-lifecycle.ts 77% 70% -7%
src/lib/onboard...ma-inference.ts 86% 80% -6%
src/lib/onboard...al-inference.ts 84% 90% +6%
src/lib/inferen...file/cleanup.ts 73% 80% +7%
src/lib/state/p...l-retirement.ts 79% 89% +10%
src/lib/readine...y-production.ts 76% 90% +14%
src/lib/onboard.../application.ts 55% 72% +17%
src/lib/onboard...mage/catalog.ts 69% 90% +21%
src/lib/securit...ig-structure.ts 0% 94% +94%

Updated September 29, 2026 17:28 UTC

@prekshivyas
prekshivyas merged commit c0fb0fe into main Sep 29, 2026
87 checks passed
@prekshivyas
prekshivyas deleted the codex/11963-forward-fence branch September 29, 2026 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[macOS/WSL2][Onboard][Regression] OpenShell dashboard forward times out and blocks sandbox onboarding

2 participants