Repository navigation
fix(onboard): reject incompatible OpenClaw base images - #7606
Conversation
Signed-off-by: San Dang <sdang@nvidia.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughThe change adds security inventory validation for OpenClaw base images, integrates it into release resolution, and tests local-build fallback when a pulled release image lacks the required inventory. ChangesBase image validation
Estimated code review effort: 3 (Moderate) | ~20 minutes Suggested reviewers: Sequence Diagram(s)sequenceDiagram
participant Onboarding
participant BaseImageResolver
participant Docker
participant LocalBuilder
Onboarding->>BaseImageResolver: resolve sandbox base image
BaseImageResolver->>Docker: pull exact release reference
BaseImageResolver->>Docker: run security inventory validation
Docker-->>BaseImageResolver: validation result
BaseImageResolver->>LocalBuilder: build current base image when invalid
LocalBuilder-->>BaseImageResolver: local image result
LocalBuilder-->>Onboarding: return resolved base image
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit d22283e in the TypeScript / code-coverage/cliThe overall coverage in commit d22283e in the Show a code coverage summary of the most impacted files.
Updated |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/lib/onboard/base-image.test.ts`:
- Around line 22-40: Strengthen the test for
openClawBaseImageHasSecurityInventory by explicitly asserting every mandatory
probe safeguard in the dockerMocks.capture command: --cap-drop ALL,
no-new-privileges, the pinned shell entrypoint, and the symlink, ownership, and
content validation fragments, while retaining the existing network, read-only,
inventory-path, and timeout assertions.
In `@src/lib/sandbox-base-image-release-resolution.test.ts`:
- Around line 211-235: Update the test around resolveSandboxBaseImage to assert
dockerMocks.pull is called exactly once and state.validateImage receives
RELEASE_REF twice in order, proving both the initial and post-refresh
validations while retaining the existing local-build expectations.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 3c973110-57aa-4805-bad8-8b913c6c8890
📒 Files selected for processing (3)
src/lib/onboard/base-image.test.tssrc/lib/onboard/base-image.tssrc/lib/sandbox-base-image-release-resolution.test.ts
PR Review Advisor — No blocking findings reportedAdvisor assessment: No blocking advisor findings reported Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: 1 optional E2E recommendation
This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
Signed-off-by: San Dang <sdang@nvidia.com>
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@test/helpers/onboard-script-mocks.cjs`:
- Around line 71-77: Strengthen the inventory probe validation in
mockOnboardRunCapture and the embedded Docker stubs so success requires the
complete probe contract, including Docker isolation and the expected
inventory-check arguments, not merely the success marker. Reuse shared helper
logic where practical. Apply this in
test/helpers/onboard-script-mocks.cjs:71-77,
test/gateway-state-reconcile-2276.test.ts:275,
test/rebuild-credential-preflight.test.ts:305,
test/rebuild-shields-auto-unlock.test.ts:249,
test/rebuild-stale-recovery.test.ts:187, and test/repro-2201.test.ts:313-316;
preserve success only for valid probes and reject weakened commands.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: dcbc2c37-801e-4b8e-a597-b83ef1174d9e
📒 Files selected for processing (8)
src/lib/onboard/base-image.test.tssrc/lib/sandbox-base-image-release-resolution.test.tstest/gateway-state-reconcile-2276.test.tstest/helpers/onboard-script-mocks.cjstest/rebuild-credential-preflight.test.tstest/rebuild-shields-auto-unlock.test.tstest/rebuild-stale-recovery.test.tstest/repro-2201.test.ts
🚧 Files skipped from review as they are similar to previous changes (2)
- src/lib/onboard/base-image.test.ts
- src/lib/sandbox-base-image-release-resolution.test.ts
Signed-off-by: San Dang <sdang@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: San Dang <sdang@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary `docs/changelog/2026-07-25.mdx` now includes the user-facing fixes that merged after #7607 and before the v0.0.96 tag. The follow-up covers safer bulk backup and clone restore behavior, policy and inference repairs, cleaner onboarding diagnostics, and OpenClaw base-image validation while leaving test-only and maintainer-internal merges out of the release entry. ## Changes - Document the Shields-safe `backup-all` flow from #7557 and the clone-specific restore pairing publication from #7608. - Record the Claude Code resolved-launcher policy repair from #7581, Hermes namespaced-model handling from #7604, and persisted Ollama proxy-token reuse from #7620. - Record OpenClaw immutable base-inventory validation from #7606, hidden route-only reservations from #7621, and clean invalid gateway-management errors from #7630. - Link the gateway lifecycle and snapshot authorities, retain #7622's already-merged Docker Engine wording, and exclude internal or test-only merges from the release entry. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [x] Tests not applicable — justification: This PR changes release-entry prose only. The changelog contract test and Fern validation cover the dated entry, published routes, and rendering requirements. - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: At exact PR head `29316da26`, a Codex Desktop documentation writer reviewed `docs/changelog/2026-07-25.mdx` against `AGENTS.md`, `WRITING.md`, and `docs/CONTRIBUTING.md`. The review confirmed that the full entry accurately reflects the merged user-visible behavior, retains #7622's existing wording, appropriately excludes internal and test-only PRs, and uses conforming terminology, structure, links, and release classification. It also confirmed that the review follow-ups use active third-person release-entry voice, name the actor and recovery requirement directly, and accurately preserve the trusted-backup, cached-release refresh, and local-build fallback constraints. The changelog test passed 6/6, and the docs build completed with 0 errors and 2 pre-existing hidden warnings. - Agent: Codex Desktop <!-- docs-review-head-sha: 29316da --> <!-- docs-review-agents-blob-sha: be20a09 --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: - Station profile/scenario: - Result: - Supporting evidence: ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: `npx vitest run test/changelog-docs.test.ts` passed 6/6 tests after the final review fix. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to this prose-only changelog change. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — exited 0 with 0 errors and 2 pre-existing hidden warnings after the final review fix. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Carlos Villela <cvillela@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Expanded the changelog to clarify persistent `policy exclude`/`policy restore` behavior across rebuilds and snapshot restores, including reporting on removed endpoints and exclusion consistency. * Updated `claude-code` preset guidance to allow the npm-installed OpenShell launcher path while maintaining endpoint/HTTP method scope. * Documented hardened handling for invalid gateway-management declarations, improved gateway/agent-version diagnostics scope, and clarified onboarding/restore credential and reasoning precedence. * Tightened bulk backup/restore guidance (safety windows, approval limits, and failure recovery) and refined OpenClaw base selection to avoid incompatible cached releases and `:latest` fallback. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Summary
OpenClaw onboarding now rejects a release base image that lacks the immutable security package inventory. The resolver refreshes the selected release once, then builds the current base locally instead of failing in the completed image's final layer.
Related Issue
Fixes #7605
Changes
latestfor a selected release.Type of Change
Quality Gates
latestsubstitution.Documentation Writer Review
no-docs-neededdocs/reference/commands.mdxalready documents the resolver behavior. The latest source-loader fixture fix changes no command, option, required user action, or output contract.DGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run check:diffpassed when hooks were skipped or unavailablenpx vitest run --project cli src/lib/onboard/base-image.test.ts src/lib/sandbox-base-image-release-resolution.test.tspassed 12 tests.npm testfor broad runtime/test-harness changes;npm run checkfor repo-wide validation/coverage changes — command/result: Not run; the change is scoped to OpenClaw base-image resolution and has focused coverage.npm run docsbuilds without warnings (doc changes only)Signed-off-by: San Dang sdang@nvidia.com
Summary by CodeRabbit
Bug Fixes
Tests