test(onboard): guard Slack channels.* allowlist sync (#4869) - #5036
Conversation
📝 WalkthroughWalkthroughA new Vitest test file validates Slack allowlist handling in ChangesSlack allowlist regression tests
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Suggested labels
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
The active OpenClaw config generator already populates channels['*']
with { enabled, requireMention, users } alongside dmPolicy / allowFrom /
groupPolicy whenever SLACK_ALLOWED_USERS is set
(scripts/generate-openclaw-config.mts), and the NVIDIA#3729 positive guard
covers the users-only path. Verified end-to-end by running the actual
production config generator (buildConfig) and the host-side collector
(collectMessagingBuildConfig) with the reporter's exact inputs on both
current main and the reporter's v0.0.59 tag: channels['*'] is emitted
correctly, so the reported empty-channels symptom does not reproduce.
Add the two missing regression guards that NVIDIA#4869 is named after, in a
dedicated test file so the existing generate-openclaw-config.test.ts
stays within its size budget:
- Backward-compatibility negative path: Slack enabled with no allowlist
leaves all four allowlist keys absent, proving they derive only from
SLACK_ALLOWED_USERS and an unset allowlist never silently broadens or
narrows channel scope.
- DM/channel scope synchronization: channels['*'].users must equal
allowFrom, pinning the exact invariant the reporter relied on so a
future change that empties channels['*'] while allowFrom stays
populated (the reported failure mode) trips the guard.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Yimo Jiang <yimoj@nvidia.com>
e8c5913 to
7cd1f27
Compare
There was a problem hiding this comment.
🧹 Nitpick comments (1)
test/generate-openclaw-config-slack-allowlist.test.ts (1)
1-1: ⚡ Quick winConsider removing
@ts-nocheckand adding proper type annotations.The
@ts-nocheckdirective disables all TypeScript type checking, reducing type safety. Consider:
- Properly typing the
buildConfigreturn value- Adding a return type annotation to
slackAccountinstead ofany- Removing the
@ts-nocheckdirectiveThis would catch type errors at compile time and make refactoring safer.
♻️ Suggested improvement
-// `@ts-nocheck` // SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. // SPDX-License-Identifier: Apache-2.0And update the
slackAccounthelper:function slackAccount(env: Record<string, string>) { return buildConfig(env as any).channels.slack.accounts.default; }If
buildConfighas proper type exports, you could also type the return value more precisely.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/generate-openclaw-config-slack-allowlist.test.ts` at line 1, Remove the file-level "`@ts-nocheck`", add proper types for buildConfig's return and for the slackAccount helper: give buildConfig an explicit exported return type (so callers can import it) and change slackAccount from "any" to a typed signature (e.g. accept env: Record<string,string> and return the precise type of channels.slack.accounts.default derived from buildConfig's return type); update the helper to call buildConfig(env as any) only if necessary and prefer using the exported buildConfig return type instead of any so TypeScript can validate accesses to channels.slack.accounts.default.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@test/generate-openclaw-config-slack-allowlist.test.ts`:
- Line 1: Remove the file-level "`@ts-nocheck`", add proper types for
buildConfig's return and for the slackAccount helper: give buildConfig an
explicit exported return type (so callers can import it) and change slackAccount
from "any" to a typed signature (e.g. accept env: Record<string,string> and
return the precise type of channels.slack.accounts.default derived from
buildConfig's return type); update the helper to call buildConfig(env as any)
only if necessary and prefer using the exported buildConfig return type instead
of any so TypeScript can validate accesses to channels.slack.accounts.default.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 4f6c3931-09cf-4bc8-a954-f973f7f37628
📒 Files selected for processing (1)
test/generate-openclaw-config-slack-allowlist.test.ts
prekshivyas
left a comment
There was a problem hiding this comment.
LGTM. Test-only regression guard for #4869, and it pins the right behavior: the scope-sync test asserts slack.channels["*"] is fully populated ({enabled, requireMention, users}) and that its users stays identical to allowFrom — directly guarding the 'channels.* comes back empty' regression the issue names. Verified main's generate-openclaw-config.mts populates channels.* from the allowlist, so the behavior is correct and the test passes (CI green). The negative path (no allowlist → keys absent) is a good backward-compat guard too. Low-risk.
<!-- patch-walker:action=sha256:4664592e4dabe18250a1e41ea73d7121d7ef19dd4cbc6c01bfe297c519a75974 --> <!-- patch-walker:manifest=sha256:95728f38d033eae61d4905337245c21043f166f5ef57eaac4908f89e2cc24d7f --> <!-- patch-walker:dependency=LangChain Deep Agents Code --> <!-- patch-walker:target=0.1.55 --> <!-- markdownlint-disable MD041 --> ## Summary Updates LangChain Deep Agents Code from 0.1.34 to 0.1.55 using the sealed NemoPin migration evidence. The implementation and requested-review fixes are complete; the PR is ready for maintainer re-review. <!-- 1-3 plain sentences: what changes and why. Describe before-and-after behavior when it applies. Follow the NemoClaw Writing Guide: https://github.com/NVIDIA/NemoClaw/blob/main/WRITING.md. Do not add unrelated prose cleanup. --> ## Related Issue No issue closure is claimed. <!-- Fixes #NNN or Closes #NNN. Remove this section if none. --> ## Changes\n\n- Keeps the dependency migration scoped to LangChain Deep Agents Code and its onboarding, validation, documentation, and managed-image checks.\n- Migrates the exact base `5bb69ed66947fbd2fab6133748866567eb520692` across 21 adjacent release ranges.\n- Changed paths: `.github/workflows/managed-images.yaml`, `agents/langchain-deepagents-code/Dockerfile`, `agents/langchain-deepagents-code/Dockerfile.base`, `agents/langchain-deepagents-code/dcode-wrapper.sh`, `agents/langchain-deepagents-code/dependency-review.md`, `agents/langchain-deepagents-code/manifest.yaml`, `agents/langchain-deepagents-code/patch-managed-deepagents-code.py`, `agents/langchain-deepagents-code/profile-plugin/pyproject.toml`, `agents/langchain-deepagents-code/profile-plugin/src/nemoclaw_deepagents_profile/__init__.py`, `agents/langchain-deepagents-code/progressive_tool_disclosure.py`, `agents/langchain-deepagents-code/requirements.in`, `agents/langchain-deepagents-code/requirements.lock`, `agents/langchain-deepagents-code/start.sh`, `agents/langchain-deepagents-code/validate-nemotron-ultra-profile.py`, `agents/langchain-deepagents-code/validate-observability.py`, `agents/langchain-deepagents-code/validate-progressive-tool-disclosure.py`, `docs/deployment/set-up-mcp-bridge.mdx`, `docs/get-started/quickstart-langchain-deepagents-code.mdx`, `src/lib/actions/sandbox/rebuild-flow-helpers.test.ts`, `src/lib/agent/base-image.test.ts`, `src/lib/agent/deep-agents-code-base-image.test.ts`, `src/lib/agent/onboard-terminal-fixtures.test.ts`, `src/lib/agent/onboard-terminal-fixtures.ts`, `src/lib/agent/onboard-terminal.test.ts`, `src/lib/inference/onboard-probes.test.ts`, `src/lib/inference/onboard-probes.ts`, `src/lib/inference/openai-validation-session.ts`, `src/lib/onboard.ts`, `src/lib/onboard/created-sandbox-finalization.test.ts`, `src/lib/onboard/created-sandbox-finalization.ts`, `src/lib/onboard/dcode-selection-drift.test.ts`, `src/lib/onboard/dcode-selection-drift.ts`, `src/lib/onboard/inference-selection-validation.test.ts`, `src/lib/onboard/machine/handlers/sandbox-checkpoint-crash-recovery.test.ts`, `src/lib/onboard/machine/handlers/sandbox.ts`, `src/lib/onboard/sandbox-lifecycle.test.ts`, `src/lib/onboard/sandbox-lifecycle.ts`, `src/lib/sandbox-base-image-agent-resolution.test.ts`, `src/lib/sandbox-base-image-release-resolution.test.ts`, `src/lib/sandbox-base-image/resolution-key.test.ts`, `test/Dockerfile.dcode-profile-missing-dependencies`, `test/cli/connect-terminal-agent.test.ts`, `test/deepagents-code-tui-startup-check.test.ts`, `test/e2e/e2e-cloud-experimental/checks/03-deepagents-code-nemotron-ultra-profile.sh`, `test/e2e/e2e-cloud-experimental/checks/04-deepagents-code-fresh-reonboard.sh`, `test/e2e/e2e-cloud-experimental/checks/10-deepagents-code-tui-startup.sh`, `test/e2e/e2e-cloud-experimental/checks/12-deepagents-code-thread-auto-approval.sh`, `test/e2e/lib/select-authorized-chat-model.mts`, `test/e2e/live/mcp-bridge-servers.ts`, `test/e2e/support/authorized-chat-model-selection.test.ts`, `test/fixtures/deepagents-progressive-disclosure-harness.py`, `test/fixtures/langchain-deepagents-code/server.py`, `test/helpers/langchain-deepagents-code-patch-fixture.ts`, `test/helpers/managed-image-buildless-e2e.ts`, `test/issue-5667-hosted-inference-model-namespace.test.ts`, `test/langchain-deepagents-code-direct-module-patch.test.ts`, `test/langchain-deepagents-code-image.test.ts`, `test/langchain-deepagents-code-nemotron-profile-plugin.test.ts`, `test/langchain-deepagents-code-progressive-tool-disclosure.test.ts`, `test/managed-image-publication-workflow.test.ts`, `test/managed-image-staging-qa-workflow.test.ts`, `test/mcp-bridge-servers.test.ts`, `test/onboard-mcp-observability-redirect.test.ts`, `test/onboard-prepared-build-context.test.ts`, `test/onboard-terminal-dashboard.test.ts`\n\n### Release ranges | Range | Commits | State | Concerns | |---|---|---|---| | 0.1.34 → 0.1.35 | `bd9bafaad3f5` → `09daab5772ff` | published | 1 | | 0.1.35 → 0.1.36 | `09daab5772ff` → `2f56309d821d` | published | 1 | | 0.1.36 → 0.1.37 | `2f56309d821d` → `def6369aed1a` | published | 2 | | 0.1.37 → 0.1.38 | `def6369aed1a` → `4338671aa1d9` | published | 4 | | 0.1.38 → 0.1.39 | `4338671aa1d9` → `8eb909a59b82` | published | 1 | | 0.1.39 → 0.1.40 | `8eb909a59b82` → `019489edb9c0` | published | 6 | | 0.1.40 → 0.1.41 | `019489edb9c0` → `d46a2cb033b8` | published | 4 | | 0.1.41 → 0.1.42 | `d46a2cb033b8` → `18679a1a88a3` | published | 3 | | 0.1.42 → 0.1.43 | `18679a1a88a3` → `e14e0adcbe78` | published | 2 | | 0.1.43 → 0.1.44 | `e14e0adcbe78` → `2b9cd08f0492` | published | 5 | | 0.1.44 → 0.1.45 | `2b9cd08f0492` → `7794b61a6e76` | published | 4 | | 0.1.45 → 0.1.46 | `7794b61a6e76` → `efa86c51fedd` | published | 1 | | 0.1.46 → 0.1.47 | `efa86c51fedd` → `8aa29ddc2833` | published | 3 | | 0.1.47 → 0.1.48 | `8aa29ddc2833` → `803b8329db7d` | published | 3 | | 0.1.48 → 0.1.49 | `803b8329db7d` → `44910bc2ef3f` | published | 0 | | 0.1.49 → 0.1.50 | `44910bc2ef3f` → `63adb9645687` | published | 2 | | 0.1.50 → 0.1.51 | `63adb9645687` → `d2b663fca277` | published | 0 | | 0.1.51 → 0.1.52 | `d2b663fca277` → `b428644d31dd` | published | 3 | | 0.1.52 → 0.1.53 | `b428644d31dd` → `0bd15dc0e1c5` | published | 2 | | 0.1.53 → 0.1.54 | `0bd15dc0e1c5` → `81258067f4c7` | published | 0 | | 0.1.54 → 0.1.55 | `81258067f4c7` → `80fe3d3cbcd2` | published | 9 | ### Concern dispositions | Concern | Surface | Planned disposition | Failure prevented | Remaining gate | |---|---|---|---|---| | `langchain-deep-agents-code-0.1.34..0.1.35-lifecycle-state-1` | lifecycle state | test | 0.1.55 reports lifecycle state: ### Features - Added a `/context` usage report for inspecting context consumption ([#5407](langchain-ai/deepagents#5407... | none | | `langchain-deep-agents-code-0.1.35..0.1.36-lifecycle-state-1` | lifecycle state | test | 0.1.54 reports lifecycle state: ### Features - Added Meta `muse-spark-1.2` to the model switcher ([#5389](langchain-ai/deepagents#5389)). - Improved di... | none | | `langchain-deep-agents-code-0.1.36..0.1.37-lifecycle-state-1` | lifecycle state | test | 0.1.53 reports lifecycle state: ### Features - Added pricing coverage with Baseten built-in overrides and local fallback overrides when `genai-prices` is missing data ([#5312](h... | none | | `langchain-deep-agents-code-0.1.36..0.1.37-runtime-topology-2` | runtime topology | test | 0.1.53 reports runtime topology: ### Features - Added pricing coverage with Baseten built-in overrides and local fallback overrides when `genai-prices` is missing data ([#5312](... | none | | `langchain-deep-agents-code-0.1.37..0.1.38-compatibility-change-1` | compatibility change | test | 0.1.52 reports compatibility change: ### Features - Hooks v2 is now generally available, with support for loading hooks from installed plugins. ([#5307](https://github.com/langc... | none | | `langchain-deep-agents-code-0.1.37..0.1.38-configuration-2` | configuration | test | 0.1.52 reports configuration: ### Features - Hooks v2 is now generally available, with support for loading hooks from installed plugins. ([#5307](https://github.com/langchain-ai... | none | | `langchain-deep-agents-code-0.1.37..0.1.38-execution-control-3` | execution control | guard | 0.1.52 reports execution control: ### Features - Hooks v2 is now generally available, with support for loading hooks from installed plugins. ([#5307](https://github.com/langchai... | none | | `langchain-deep-agents-code-0.1.37..0.1.38-lifecycle-state-4` | lifecycle state | test | 0.1.52 reports lifecycle state: ### Features - Hooks v2 is now generally available, with support for loading hooks from installed plugins. ([#5307](https://github.com/langchain-... | none | | `langchain-deep-agents-code-0.1.38..0.1.39-configuration-1` | configuration | test | 0.1.51 reports configuration: ### Features - The status bar and usage view now show the running session cost. ([#5036](langchain-ai/deepagents#5036)) -... | none | | `langchain-deep-agents-code-0.1.39..0.1.40-compatibility-change-1` | compatibility change | test | 0.1.50 reports compatibility change: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feed... | none | | `langchain-deep-agents-code-0.1.39..0.1.40-execution-control-2` | execution control | guard | 0.1.50 reports execution control: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feedbac... | none | | `langchain-deep-agents-code-0.1.39..0.1.40-lifecycle-state-3` | lifecycle state | test | 0.1.50 reports lifecycle state: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feedback ... | none | | `langchain-deep-agents-code-0.1.39..0.1.40-packaging-artifact-4` | packaging artifact | test | 0.1.50 reports packaging artifact: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feedba... | none | | `langchain-deep-agents-code-0.1.39..0.1.40-runtime-topology-5` | runtime topology | test | 0.1.50 reports runtime topology: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feedback... | none | | `langchain-deep-agents-code-0.1.39..0.1.40-security-identity-6` | security identity | guard | 0.1.50 reports security identity: ### Highlights - Added project hooks workspace trust and expanded Hooks v2 support with client and server lifecycle events plus runtime feedbac... | none | | `langchain-deep-agents-code-0.1.40..0.1.41-compatibility-change-1` | compatibility change | test | 0.1.49 reports compatibility change: ### Features - Added recognition for LangSmith Gateway credentials. ([#5042](langchain-ai/deepagents#5042)) - Adde... | none | | `langchain-deep-agents-code-0.1.40..0.1.41-execution-control-2` | execution control | guard | 0.1.49 reports execution control: ### Features - Added recognition for LangSmith Gateway credentials. ([#5042](langchain-ai/deepagents#5042)) - Added s... | none | | `langchain-deep-agents-code-0.1.40..0.1.41-lifecycle-state-3` | lifecycle state | test | 0.1.49 reports lifecycle state: ### Features - Added recognition for LangSmith Gateway credentials. ([#5042](langchain-ai/deepagents#5042)) - Added sla... | none | | `langchain-deep-agents-code-0.1.40..0.1.41-runtime-topology-4` | runtime topology | test | 0.1.49 reports runtime topology: ### Features - Added recognition for LangSmith Gateway credentials. ([#5042](langchain-ai/deepagents#5042)) - Added sl... | none | | `langchain-deep-agents-code-0.1.41..0.1.42-compatibility-change-1` | compatibility change | test | 0.1.48 reports compatibility change: ### Features - Added Fireworks `kimi-k3`, GLM-5.2-Fast, and Kimi-K3 to model selection and recommended models. ([#5082](https://github.com/l... | none | | `langchain-deep-agents-code-0.1.41..0.1.42-execution-control-2` | execution control | guard | 0.1.48 reports execution control: ### Features - Added Fireworks `kimi-k3`, GLM-5.2-Fast, and Kimi-K3 to model selection and recommended models. ([#5082](https://github.com/lang... | none | | `langchain-deep-agents-code-0.1.41..0.1.42-lifecycle-state-3` | lifecycle state | test | 0.1.48 reports lifecycle state: ### Features - Added Fireworks `kimi-k3`, GLM-5.2-Fast, and Kimi-K3 to model selection and recommended models. ([#5082](https://github.com/langch... | none | | `langchain-deep-agents-code-0.1.42..0.1.43-compatibility-change-1` | compatibility change | test | 0.1.47 reports compatibility change: ### Features - Added `yolo` mode to the `Shift+Tab` approval cycle ([#5035](langchain-ai/deepagents#5035)). - Show... | none | | `langchain-deep-agents-code-0.1.42..0.1.43-execution-control-2` | execution control | guard | 0.1.47 reports execution control: ### Features - Added `yolo` mode to the `Shift+Tab` approval cycle ([#5035](langchain-ai/deepagents#5035)). - Show th... | none | | `langchain-deep-agents-code-0.1.43..0.1.44-compatibility-change-1` | compatibility change | test | 0.1.46 reports compatibility change: ### Highlights - Auto mode is now generally available. [#4957](langchain-ai/deepagents#4957) - Added configurable ... | none | | `langchain-deep-agents-code-0.1.43..0.1.44-configuration-2` | configuration | test | 0.1.46 reports configuration: ### Highlights - Auto mode is now generally available. [#4957](langchain-ai/deepagents#4957) - Added configurable Auto go... | none | | `langchain-deep-agents-code-0.1.43..0.1.44-execution-control-3` | execution control | guard | 0.1.46 reports execution control: ### Highlights - Auto mode is now generally available. [#4957](langchain-ai/deepagents#4957) - Added configurable Aut... | none | | `langchain-deep-agents-code-0.1.43..0.1.44-protocol-schema-4` | protocol schema | test | 0.1.46 reports protocol schema: ### Highlights - Auto mode is now generally available. [#4957](langchain-ai/deepagents#4957) - Added configurable Auto ... | none | | `langchain-deep-agents-code-0.1.43..0.1.44-security-identity-5` | security identity | guard | 0.1.46 reports security identity: ### Highlights - Auto mode is now generally available. [#4957](langchain-ai/deepagents#4957) - Added configurable Aut... | none | | `langchain-deep-agents-code-0.1.44..0.1.45-compatibility-change-1` | compatibility change | test | 0.1.45 reports compatibility change: ### Features - Added the Hooks v2 execution engine and typed hooks data models ([#4880](langchain-ai/deepagents#48... | none | | `langchain-deep-agents-code-0.1.44..0.1.45-execution-control-2` | execution control | guard | 0.1.45 reports execution control: ### Features - Added the Hooks v2 execution engine and typed hooks data models ([#4880](langchain-ai/deepagents#4880)... | none | | `langchain-deep-agents-code-0.1.44..0.1.45-lifecycle-state-3` | lifecycle state | test | 0.1.45 reports lifecycle state: ### Features - Added the Hooks v2 execution engine and typed hooks data models ([#4880](langchain-ai/deepagents#4880), ... | none | | `langchain-deep-agents-code-0.1.44..0.1.45-packaging-artifact-4` | packaging artifact | test | 0.1.45 reports packaging artifact: ### Features - Added the Hooks v2 execution engine and typed hooks data models ([#4880](langchain-ai/deepagents#4880... | none | | `langchain-deep-agents-code-0.1.45..0.1.46-runtime-topology-1` | runtime topology | test | 0.1.44 reports runtime topology: ### Bug Fixes - Improved approval handling by hiding the `Auto` option when it isn't eligible and moving Auto mode path checks off the event loo... | none | | `langchain-deep-agents-code-0.1.46..0.1.47-compatibility-change-1` | compatibility change | test | 0.1.43 reports compatibility change: ### Features - Added classifier-backed Auto approval mode behind `DEEPAGENTS_CODE_EXPERIMENTAL=1` ([#4804](https://github.com/langchain-ai/d... | none | | `langchain-deep-agents-code-0.1.46..0.1.47-execution-control-2` | execution control | guard | 0.1.43 reports execution control: ### Features - Added classifier-backed Auto approval mode behind `DEEPAGENTS_CODE_EXPERIMENTAL=1` ([#4804](https://github.com/langchain-ai/deep... | none | | `langchain-deep-agents-code-0.1.46..0.1.47-lifecycle-state-3` | lifecycle state | test | 0.1.43 reports lifecycle state: ### Features - Added classifier-backed Auto approval mode behind `DEEPAGENTS_CODE_EXPERIMENTAL=1` ([#4804](https://github.com/langchain-ai/deepag... | none | | `langchain-deep-agents-code-0.1.47..0.1.48-compatibility-change-1` | compatibility change | test | 0.1.42 reports compatibility change: ### Features - Plugins are now generally available. ([#4797](langchain-ai/deepagents#4797)) - Added search to the ... | none | | `langchain-deep-agents-code-0.1.47..0.1.48-execution-control-2` | execution control | guard | 0.1.42 reports execution control: ### Features - Plugins are now generally available. ([#4797](langchain-ai/deepagents#4797)) - Added search to the plu... | none | | `langchain-deep-agents-code-0.1.47..0.1.48-lifecycle-state-3` | lifecycle state | test | 0.1.42 reports lifecycle state: ### Features - Plugins are now generally available. ([#4797](langchain-ai/deepagents#4797)) - Added search to the plugi... | none | | `langchain-deep-agents-code-0.1.49..0.1.50-compatibility-change-1` | compatibility change | test | 0.1.40 reports compatibility change: ### Features - Added plugin marketplace support ([#4554](langchain-ai/deepagents#4554)). - Added an “always allow”... | none | | `langchain-deep-agents-code-0.1.49..0.1.50-execution-control-2` | execution control | guard | 0.1.40 reports execution control: ### Features - Added plugin marketplace support ([#4554](langchain-ai/deepagents#4554)). - Added an “always allow” op... | none | | `langchain-deep-agents-code-0.1.51..0.1.52-compatibility-change-1` | compatibility change | test | 0.1.38 reports compatibility change: ### Features * Improve `/goal` criteria UX ([#4694](langchain-ai/deepagents#4694)) ([06f46ff](https://github.com/l... | none | | `langchain-deep-agents-code-0.1.51..0.1.52-configuration-2` | configuration | test | 0.1.38 reports configuration: ### Features * Improve `/goal` criteria UX ([#4694](langchain-ai/deepagents#4694)) ([06f46ff](https://github.com/langchai... | none | | `langchain-deep-agents-code-0.1.51..0.1.52-lifecycle-state-3` | lifecycle state | test | 0.1.38 reports lifecycle state: ### Features * Improve `/goal` criteria UX ([#4694](langchain-ai/deepagents#4694)) ([06f46ff](https://github.com/langch... | none | | `langchain-deep-agents-code-0.1.52..0.1.53-configuration-1` | configuration | test | 0.1.37 reports configuration: ### Features * Add Meta model provider ([#4650](langchain-ai/deepagents#4650)) ([70829c5](https://github.com/langchain-ai... | none | | `langchain-deep-agents-code-0.1.52..0.1.53-security-identity-2` | security identity | guard | 0.1.37 reports security identity: ### Features * Add Meta model provider ([#4650](langchain-ai/deepagents#4650)) ([70829c5](https://github.com/langchai... | none | | `langchain-deep-agents-code-0.1.54..0.1.55-compatibility-change-1` | compatibility change | test | 0.1.35 reports compatibility change: ### Features * Restore interrupted prompt to input on ESC ([#4544](langchain-ai/deepagents#4544)) ([fccf037](https... | none | | `langchain-deep-agents-code-0.1.54..0.1.55-configuration-2` | configuration | test | 0.1.35 reports configuration: ### Features * Restore interrupted prompt to input on ESC ([#4544](langchain-ai/deepagents#4544)) ([fccf037](https://gith... | none | | `langchain-deep-agents-code-0.1.54..0.1.55-execution-control-3` | execution control | guard | 0.1.35 reports execution control: ### Features * Restore interrupted prompt to input on ESC ([#4544](langchain-ai/deepagents#4544)) ([fccf037](https://... | none | | `langchain-deep-agents-code-0.1.54..0.1.55-lifecycle-state-4` | lifecycle state | test | 0.1.35 reports lifecycle state: ### Features * Restore interrupted prompt to input on ESC ([#4544](langchain-ai/deepagents#4544)) ([fccf037](https://gi... | none | | `langchain-deep-agents-code-0.1.54..0.1.55-protocol-schema-5` | protocol schema | test | 0.1.35 reports protocol schema: ### Features * Restore interrupted prompt to input on ESC ([#4544](langchain-ai/deepagents#4544)) ([fccf037](https://gi... | none | | `langchain-deep-agents-code-0.1.54..0.1.55-code-impact-configuration-1` | mapped configuration | test | The exact-ref diff reports configuration changes in .pre-commit-config.yaml, libs/acp/deepagents_acp/server.py, libs/acp/tests/test_agent.py. Mapped NemoClaw examples: src/lib/a... | none | | `langchain-deep-agents-code-0.1.54..0.1.55-code-impact-contract-or-schema-2` | mapped contract or schema | test | The exact-ref diff reports contract or schema changes in libs/acp/deepagents_acp/_version.py, libs/acp/deepagents_acp/server.py, libs/code/deepagents_code/_ask_user_types.py. Ma... | none | | `langchain-deep-agents-code-0.1.54..0.1.55-code-impact-security-3` | mapped security | test | The exact-ref diff reports security changes in libs/code/deepagents_code/_cli_context.py, libs/code/deepagents_code/_env_vars.py, libs/code/deepagents_code/_repository_bounds.py... | none | | `langchain-deep-agents-code-0.1.54..0.1.55-code-impact-test-4` | mapped test | test | The exact-ref diff reports test changes in libs/acp/tests/chat_model.py, libs/acp/tests/test_agent.py, libs/code/tests/integration_tests/benchmarks/test_local_context_benchmarks... | none | ### Immutable artifacts | Artifact | SHA-256 | |---|---| | deepagents_code-0.1.55-py3-none-any.whl | `3a0d3e332f132d0e…` | | deepagents_code-0.1.55.tar.gz | `91c30b62cb96d5e8…` | ### Validation receipt | Gate | Current result | |---|---| | targeted | Pass — 130 affected local tests, commit hooks, growth guardrails, and pre-push typechecks passed on the unchanged PR patch now at `78268b19e` | | full-e2e | In progress on the latest PR commit — all required checks pass; three non-required managed-image jobs are still running | <!-- List concrete changes. If this adds an abstraction, configuration, fallback, migration, or compatibility path, name its current requirement and consumer, explain why a direct change is insufficient, and identify the test that protects it. --> ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [x] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [x] Sensitive-path review completed or maintainer-approved waiver recorded — CodeRabbit completed successfully on the unchanged PR patch and all inline review threads are resolved; human re-review remains requested. - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: `docs/deployment/set-up-mcp-bridge.mdx` and `docs/get-started/quickstart-langchain-deepagents-code.mdx` accurately document the changed Deep Agents Code behavior and versions. The documented deepagents-code 0.1.55 and deepagents 0.7.5 versions match the manifest, inputs, lockfile, and profile plugin. `npm run docs` passed with 0 errors and two pre-existing Fern warnings. - Agent: Codex Desktop <!-- docs-review-head-sha: 78268b1 --> <!-- docs-review-agents-blob-sha: e30afb2 --> ## DGX Station Hardware Evidence <!-- Required only when scripts/prepare-dgx-station-host.sh changes. Maintainers must review the linked evidence before approving or merging. This is human-reviewed evidence, not authenticated hardware provenance. Exceptional bypasses use existing repository governance and must be documented on the PR. --> - [ ] Tested on DGX Station - Tested commit: - Station profile/scenario: - Result: - Supporting evidence: ## Verification <!-- Check each applicable item only when supported by the requested evidence. Run targeted tests once per relevant change set and rerun after later edits or hook autofixes that can affect the tested behavior. Do not rerun hook-covered checks. --> - [x] PR description includes a `Signed-off-by:` line and all 81 commits appear as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed on the unchanged PR patch now at `78268b19e` - [x] Targeted behavior tests pass for the current change set — affected local suites: 130/130; growth guardrails passed - [ ] Applicable broad gate passed — all required GitHub checks pass; non-required managed-image validation is still in progress - [x] Quality Gates section completed with required justifications - [x] No secrets, API keys, or credentials committed; gitleaks passed - [ ] `npm run docs` builds without warnings (doc changes only) - [ ] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- <!-- DCO sign-off is required in this PR description, and every commit must appear as Verified in GitHub. Run: git config user.name && git config user.email --> Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> <!-- patch-walker-status:start --> ## NemoPatch latest PR commit status - Status: **ready for maintainer re-review** - Latest PR commit: `78268b19e8229ffbc2a0591ad310caf96aab7fa6` - Checked: 2026-08-19T19:39:34Z - Merge: GitHub reports **MERGEABLE**; the local patch check against current `upstream/main` is clean. - Review: all 8 inline review threads are resolved and no new review finding was posted for the unchanged patch. Human approval remains required. - CI: all required checks pass. Three broader non-required managed-image jobs are still running with no deterministic failure at this check. - External advisor infrastructure: GPT-5.6 Terra and Nemotron 3 Ultra failed with `investigate omitted required analysis`; the trusted publisher reports 0 blockers, 0 warnings, 0 suggestions, and no follow-up needed. <!-- patch-walker-status:end --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Upgraded Deep Agents Code support to 0.1.55 and Deep Agents to 0.7.5. * Expanded approval controls with manual, automatic, startup, and YOLO modes. * Tool search and discovery now include registered tools across agents and subagents. * Added gateway-aware sandbox operations and authorized chat-model selection during onboarding. * **Bug Fixes** * Improved sandbox crash recovery and identity detection. * Strengthened MCP result validation and protected private inference endpoints. * **Documentation** * Updated setup and quickstart guidance for supported versions. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> Signed-off-by: Prekshiv <prekshiv@nvidia.com>
Summary
Hardens the Slack allowlist regression guard for #4869. The active OpenClaw
config generator (
scripts/generate-openclaw-config.mts) already emitschannels["*"] = { enabled: true, requireMention: true, users: [...] }alongside
dmPolicy/allowFrom/groupPolicywheneverSLACK_ALLOWED_USERSis set, and the
#3729positive guard covers the users-only path. This PR addsthe two regression guards the issue is named after — the backward-compatibility
negative path and the DM/channel scope-synchronization invariant — so the
reported failure mode (empty
channels["*"]whileallowFromis populated)cannot regress unnoticed.
Related Issue
Fixes #4869
Changes
test/generate-openclaw-config-slack-allowlist.test.ts(kept separate sogenerate-openclaw-config.test.tsstays within its size budget):allowlist keys (
dmPolicy,allowFrom,groupPolicy,channels) absent,proving they derive only from
SLACK_ALLOWED_USERSand that an unsetallowlist never silently broadens (listen-everywhere) or narrows (disable)
channel scope.
channels["*"].usersmust equalallowFrom, pinningthe exact security invariant the reporter relied on (DM and channel scopes
stay in lockstep, both sourced from the same member IDs).
Type of Change
Investigation
The reported
channels["*"]: {}does not reproduce on currentmain. Thetriage note pointed at the manifest render path (
{{allowedIds.slack.channels}}in
src/lib/messaging/channels/slack/manifest.ts), but that render plan is neverapplied during onboarding:
applyAgentConfigAtOpenShellhas no production callsite in any commit, and nothing resolves the
{{allowedIds.*}}refs. The solewriter of
/sandbox/.openclaw/openclaw.jsonisscripts/generate-openclaw-config.mts,which writes
dmPolicy/allowFrom/groupPolicyand thechannels["*"]block in the same branch — so the policies-present-but-channels-empty symptom is
not producible from the generator. Both the env-export and interactive-wizard
input paths populate
SLACK_ALLOWED_USERS(the config-prompt hook writes it backto the environment the generator reads), so neither path can drop the channel
scope. The most likely cause of the reporter's observation is a stale Docker
build layer reusing a pre-
#3729openclaw.json.Verification
Reporter-workflow E2E for the config-generation step, run against the exact
production code that writes the inspected artifact:
Ran
buildConfigfromscripts/generate-openclaw-config.mts(the script thesandbox image build executes to write
/sandbox/.openclaw/openclaw.json) withthe reporter's exact inputs (
SLACK_ALLOWED_USERS=U_DUMMY_ALLOW1,U_DUMMY_ALLOW2,no
SLACK_ALLOWED_CHANNELS). Result matches the issue's expected output:Confirmed the same correct output on the reporter's CLI version (
v0.0.59tag).Confirmed the host-side collector
collectMessagingBuildConfigmapsSLACK_ALLOWED_USERS→messagingAllowedIds.slack, which feedsNEMOCLAW_MESSAGING_ALLOWED_IDS_B64consumed by the generator.vitest run test/generate-openclaw-config-slack-allowlist.test.ts→ 2/2 pass.vitest run test/generate-openclaw-config.test.ts→ 135/135 pass (existing#3729positive guards included).A full live
nemoclaw onboardto inspect the in-sandbox config was not run tocompletion: the shared OpenShell gateway on this host is continuously in use by
concurrent worktree onboards, and a fresh onboard switches the gateway driver and
disrupts those active runs. The
buildConfigexecution above exercises the exactcode path that produces the file the reporter inspects.
npx prek run --all-files(lint/format on changed files)Signed-off-by: Yimo Jiang yimoj@nvidia.com