Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
49 commits
Select commit Hold shift + click to select a range
90a73b1
fix(messaging): use native websocket credential rewrite
ericksoa May 10, 2026
84c189f
fix(messaging): remove credential rewrite bridges
ericksoa May 11, 2026
b77051d
fix(onboard): fail closed gateway lifecycle cleanup
ericksoa May 11, 2026
b09e6a9
fix(onboard): keep failed gateway cleanup non-reusable
ericksoa May 11, 2026
c9ba631
test(e2e): validate fake slack api port
ericksoa May 11, 2026
72a6e69
Merge remote-tracking branch 'origin/main' into fix/native-messaging-…
ericksoa May 11, 2026
316baae
Merge remote-tracking branch 'origin/main' into fix/native-messaging-…
ericksoa May 11, 2026
c05172c
Merge remote-tracking branch 'origin/main' into fix/native-messaging-…
ericksoa May 11, 2026
0d4a3f7
Merge remote-tracking branch 'origin/main' into fix/native-messaging-…
ericksoa May 12, 2026
6d82117
ci: pin openshell pr for messaging nightly
ericksoa May 12, 2026
bd0e346
ci: route openshell pr pin through installer
ericksoa May 12, 2026
3205ab4
ci: preinstall openshell pin for messaging e2e
ericksoa May 12, 2026
752ae55
ci: avoid removing openshell install dir
ericksoa May 12, 2026
d33f54d
ci: bundle z3 for openshell pr build
ericksoa May 12, 2026
ae06349
ci: provide cmake for openshell pr build
ericksoa May 12, 2026
2c8c488
ci: build openshell pin with release toolchain
ericksoa May 12, 2026
b696036
ci: keep openshell pr helper executable
ericksoa May 12, 2026
c3f4161
ci: allow openshell ci image pull
ericksoa May 12, 2026
1d848e5
ci: pass openshell build script to container
ericksoa May 12, 2026
a614ab3
ci: trust openshell mise config in container
ericksoa May 12, 2026
b1806c3
Revert "ci: trust openshell mise config in container"
ericksoa May 12, 2026
c288048
Revert "ci: pass openshell build script to container"
ericksoa May 12, 2026
dc62ddc
Revert "ci: allow openshell ci image pull"
ericksoa May 12, 2026
353d18f
Revert "ci: keep openshell pr helper executable"
ericksoa May 12, 2026
ff501f0
Revert "ci: build openshell pin with release toolchain"
ericksoa May 12, 2026
8141666
Revert "ci: provide cmake for openshell pr build"
ericksoa May 12, 2026
79ea011
Revert "ci: bundle z3 for openshell pr build"
ericksoa May 12, 2026
4edbad0
Revert "ci: avoid removing openshell install dir"
ericksoa May 12, 2026
dd826fb
Revert "ci: preinstall openshell pin for messaging e2e"
ericksoa May 12, 2026
b8ec6cc
Revert "ci: route openshell pr pin through installer"
ericksoa May 12, 2026
3aab8d9
Revert "ci: pin openshell pr for messaging nightly"
ericksoa May 12, 2026
4ad426b
ci: build OpenShell PR for messaging nightly
ericksoa May 12, 2026
645870c
ci: trust OpenShell mise config in nightly build
ericksoa May 12, 2026
f8df884
ci: fix nightly after OpenShell PR pin
ericksoa May 12, 2026
d18ed4f
ci: prefetch Z3 for OpenShell nightly build
ericksoa May 12, 2026
483f165
fix: probe Docker-driver gateway health endpoint
ericksoa May 12, 2026
cc05227
ci: refresh OpenShell PR nightly pin
ericksoa May 12, 2026
f0b8e01
fix: probe Docker-driver gRPC health
ericksoa May 12, 2026
8e04c7b
ci: build OpenShell main for messaging nightly
ericksoa May 12, 2026
799839d
ci: mark OpenShell main nightly build as dev channel
ericksoa May 12, 2026
816a6c0
Merge remote-tracking branch 'origin/main' into fix/native-messaging-…
ericksoa May 12, 2026
2e1d57b
fix: address CodeRabbit feedback
ericksoa May 12, 2026
afb4896
test: stabilize macos debug timeout
ericksoa May 12, 2026
e7baa6d
Merge remote-tracking branch 'origin/main' into fix/native-messaging-…
ericksoa May 12, 2026
7e83675
Merge remote-tracking branch 'origin/main' into fix/native-messaging-…
ericksoa May 12, 2026
aa3c8fd
chore: require openshell 0.0.39
ericksoa May 12, 2026
36ab7f8
fix: avoid openshell e2e wrapper recursion
ericksoa May 12, 2026
e7436de
Merge remote-tracking branch 'origin/main' into fix/native-messaging-…
ericksoa May 12, 2026
ad951f8
test: expect openshell 0.0.39 in gateway upgrade e2e
ericksoa May 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 9 additions & 8 deletions .github/workflows/nightly-e2e.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,7 @@
# cloud-e2e Cloud inference (NVIDIA Endpoint API) on ubuntu-latest.
# messaging-providers-e2e Validates messaging credential provider/placeholder/L7-proxy chain
# for Telegram + Discord + Slack. Uses fake tokens. Slack additionally
# exercises the slack-token-rewriter Bolt-shape → canonical placeholder
# translation (#2085). See PR #1081.
# exercises OpenShell provider-shaped alias resolution (#2085 follow-up).
# messaging-compatible-endpoint-e2e
# Validates Telegram + OpenAI-compatible endpoint inference routing
# through inference.local with a hermetic local mock (#2766).
Expand All @@ -21,7 +20,7 @@
# gateway stop/start, verify sandbox + workspace + inference).
# openshell-gateway-upgrade-e2e
# Validates real v0.0.36 curl install upgrade into
# OpenShell 0.0.37 with pre-upgrade backup, restored
# the current supported OpenShell with pre-upgrade backup, restored
# agent state, and the same agent type running.
# gateway-health-honest-e2e
# Coverage guard for #3111: onboard must not log
Expand All @@ -36,7 +35,7 @@
# hermes-discord-e2e Hermes Discord onboarding — validates the top-level Hermes
# Discord schema plus OpenShell placeholder/token isolation.
# hermes-slack-e2e Hermes Slack onboarding — validates the Hermes Slack policy,
# Slack providers, and Python placeholder egress path.
# Slack providers, and OpenShell credential rewrite path.
# openclaw-inference-switch-e2e
# Switches a running OpenClaw sandbox with `nemoclaw inference set`
# and verifies route, openclaw.json, hashes, and live requests.
Expand Down Expand Up @@ -1430,19 +1429,18 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@v6

- name: Install NemoClaw
env:
NVIDIA_API_KEY: ${{ secrets.NVIDIA_API_KEY }}
NEMOCLAW_NON_INTERACTIVE: "1"
NEMOCLAW_ACCEPT_THIRD_PARTY_SOFTWARE: "1"
NEMOCLAW_SANDBOX_NAME: "e2e-double-install"
run: bash install.sh --non-interactive --yes-i-accept-third-party-software
- name: Run double onboard E2E test
env:
NVIDIA_API_KEY: ${{ secrets.NVIDIA_API_KEY }}
NEMOCLAW_NON_INTERACTIVE: "1"
NEMOCLAW_ACCEPT_THIRD_PARTY_SOFTWARE: "1"
NEMOCLAW_E2E_INSTALL_SANDBOX_NAME: "e2e-double-install"
run: |
[ -f "$HOME/.bashrc" ] && source "$HOME/.bashrc" 2>/dev/null || true
export NVM_DIR="${NVM_DIR:-$HOME/.nvm}"
Expand All @@ -1469,19 +1467,18 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@v6

- name: Install NemoClaw
env:
NVIDIA_API_KEY: ${{ secrets.NVIDIA_API_KEY }}
NEMOCLAW_NON_INTERACTIVE: "1"
NEMOCLAW_ACCEPT_THIRD_PARTY_SOFTWARE: "1"
NEMOCLAW_SANDBOX_NAME: "e2e-repair-install"
run: bash install.sh --non-interactive --yes-i-accept-third-party-software
- name: Run onboard repair E2E test
env:
NVIDIA_API_KEY: ${{ secrets.NVIDIA_API_KEY }}
NEMOCLAW_NON_INTERACTIVE: "1"
NEMOCLAW_ACCEPT_THIRD_PARTY_SOFTWARE: "1"
NEMOCLAW_E2E_INSTALL_SANDBOX_NAME: "e2e-repair-install"
run: |
[ -f "$HOME/.bashrc" ] && source "$HOME/.bashrc" 2>/dev/null || true
export NVM_DIR="${NVM_DIR:-$HOME/.nvm}"
Expand All @@ -1508,6 +1505,7 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@v6

- name: Install NemoClaw
env:
NVIDIA_API_KEY: ${{ secrets.NVIDIA_API_KEY }}
Expand Down Expand Up @@ -1545,6 +1543,7 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@v6

- name: Install NemoClaw
env:
NVIDIA_API_KEY: ${{ secrets.NVIDIA_API_KEY }}
Expand Down Expand Up @@ -1583,6 +1582,7 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@v6

- name: Install NemoClaw and onboard sandbox
env:
NVIDIA_API_KEY: ${{ secrets.NVIDIA_API_KEY }}
Expand Down Expand Up @@ -1624,6 +1624,7 @@ jobs:
steps:
- name: Checkout
uses: actions/checkout@v6

- name: Install NemoClaw and onboard sandbox
env:
NVIDIA_API_KEY: ${{ secrets.NVIDIA_API_KEY }}
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/sandbox-images-and-e2e.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@ jobs:
docker run --rm --user sandbox nemoclaw-hermes-production \
test -r /opt/nemoclaw-blueprint/blueprint.yaml
docker run --rm --user sandbox nemoclaw-hermes-production \
test -x /usr/local/bin/nemoclaw-decode-proxy
test ! -e /usr/local/bin/nemoclaw-decode-proxy
docker run --rm --user sandbox nemoclaw-hermes-production \
test -x /usr/local/bin/nemoclaw-start

Expand Down
1 change: 0 additions & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -245,7 +245,6 @@ RUN chmod 755 /usr/local/bin/nemoclaw-start /usr/local/bin/nemoclaw-codex-acp \
/usr/local/lib/nemoclaw/sandbox-init.sh \
/usr/local/lib/nemoclaw/generate-openclaw-config.py \
&& if [ -d /usr/local/lib/nemoclaw/preloads ]; then find /usr/local/lib/nemoclaw/preloads -type f -name '*.js' -exec chmod 644 {} +; fi \
&& if [ -f /usr/local/lib/nemoclaw/ws-proxy-fix.js ]; then chmod 644 /usr/local/lib/nemoclaw/ws-proxy-fix.js; fi \
&& chmod 755 /usr/local/share/nemoclaw \
/usr/local/share/nemoclaw/openclaw-plugins \
&& find /usr/local/share/nemoclaw/openclaw-plugins -type d -exec chmod 755 {} + \
Expand Down
16 changes: 4 additions & 12 deletions agents/hermes/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -29,28 +29,20 @@ RUN (apt-get remove --purge -y gcc gcc-12 g++ g++-12 cpp cpp-12 make \
&& rm -rf /var/lib/apt/lists/*

# Hermes v2026.4.13+ auto-detects HTTPS_PROXY and skips fallback-IP
# transport when a proxy is present. The sandbox proxy chain
# (decode-proxy -> OpenShell L7 proxy) handles REST credential placeholder
# rewriting and hostname-based policy enforcement. A Hermes-only local Discord
# facade handles discord.py's Gateway session inside the sandbox and forwards
# REST through the same placeholder-substitution path.
# transport when a proxy is present. OpenShell handles REST credential
# placeholder rewriting, hostname-based policy enforcement, and native
# WebSocket credential rewrite at the egress boundary.
ENV HERMES_TELEGRAM_DISABLE_FALLBACK_IPS=1

# Copy NemoClaw plugin for Hermes (Python-based)
COPY agents/hermes/plugin/ /opt/nemoclaw-hermes-plugin/
RUN chmod -R a+rX /opt/nemoclaw-hermes-plugin/

# Copy config generator, Discord facade, and URL-decode proxy
# Copy config generator
COPY agents/hermes/generate-config.ts /opt/nemoclaw-hermes-config/generate-config.ts
COPY agents/hermes/config/ /opt/nemoclaw-hermes-config/config/
RUN find /opt/nemoclaw-hermes-config -type d -exec chmod 755 {} + \
&& find /opt/nemoclaw-hermes-config -type f -exec chmod 444 {} +
COPY agents/hermes/decode-proxy.py /usr/local/bin/nemoclaw-decode-proxy
COPY agents/hermes/discord-facade.py /usr/local/bin/nemoclaw-discord-facade
COPY agents/hermes/discord-preload/ /opt/nemoclaw-hermes-discord-preload/
RUN chmod 755 /usr/local/bin/nemoclaw-decode-proxy /usr/local/bin/nemoclaw-discord-facade \
&& find /opt/nemoclaw-hermes-discord-preload -type d -exec chmod 755 {} + \
&& find /opt/nemoclaw-hermes-discord-preload -type f -exec chmod 444 {} +

# Copy blueprint (shared infrastructure)
COPY nemoclaw-blueprint/ /opt/nemoclaw-blueprint/
Expand Down
5 changes: 0 additions & 5 deletions agents/hermes/config/messaging-config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,6 @@ const CHANNEL_TOKEN_ENVS: Record<string, string[]> = {
slack: ["SLACK_BOT_TOKEN", "SLACK_APP_TOKEN"],
};

const HERMES_DISCORD_PROXY = "http://127.0.0.1:3129";
const HERMES_DISCORD_FACADE = "http://127.0.0.1:3130";

export function buildMessagingEnvLines(
enabledChannels: Set<string>,
allowedIds: MessagingAllowedIds,
Expand All @@ -25,8 +22,6 @@ export function buildMessagingEnvLines(
envLines.push(`${envKey}=${buildTokenPlaceholder(channel, envKey)}`);
}
if (channel === "discord") {
envLines.push(`DISCORD_PROXY=${HERMES_DISCORD_PROXY}`);
envLines.push(`NEMOCLAW_DISCORD_FACADE_URL=${HERMES_DISCORD_FACADE}`);
const guildIds = Object.keys(discordGuilds).filter(Boolean);
if (guildIds.length > 0) {
envLines.push(`NEMOCLAW_DISCORD_GUILD_IDS=${guildIds.join(",")}`);
Expand Down
195 changes: 0 additions & 195 deletions agents/hermes/decode-proxy.py

This file was deleted.

Loading
Loading