Repository navigation
fix(onboard): continue onboarding when Homebrew refuses the pinned OpenShell tap #7739
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
cv
merged 47 commits into
NVIDIA:main
from
harjothkhara:fix/7707-homebrew-untrusted-tap
Aug 13, 2026
Merged
Changes from 4 commits
Commits
Show all changes
47 commits
Select commit
Hold shift + click to select a range
d84f839
fix(onboard): continue onboarding when Homebrew cannot confirm the Op…
harjothkhara 8350421
docs(reference): document the standalone fallback for unconfirmed Hom…
harjothkhara cb9d771
fix(onboard): limit the Homebrew fallback to the pinned-tap load refusal
harjothkhara d37a028
fix(onboard): name the pinned-tap refusal precisely in the fallback w…
harjothkhara 3b75153
fix(onboard): keep a loaded Homebrew launchd service fatal during tap…
harjothkhara ab87091
fix(onboard): fail closed when the launchd probe cannot answer
harjothkhara 48d2974
fix(onboard): treat an unrecognized launchctl failure as an unknown u…
harjothkhara b832b25
merge(main): sync current main
apurvvkumaria 9fe39c1
fix(onboard): recognize only missing launchd unit
apurvvkumaria d7b474c
merge(onboard): preserve launchd probe hardening
apurvvkumaria b7f5338
merge(main): sync current main
apurvvkumaria c182d79
merge(main): sync current main
apurvvkumaria 717ecb2
merge(main): sync current main
apurvvkumaria 249b9f7
merge(main): sync current main
apurvvkumaria bf489d7
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cjagwani cdbac77
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cjagwani 26b3b0f
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cjagwani eb958ff
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cjagwani fcc6702
merge: sync Homebrew fallback with main
cjagwani 46debbf
merge(main): refresh #7739 against current main
cv 3f8825b
fix(onboard): harden Homebrew fallback diagnostics
cv 1ced5be
merge(main): refresh #7739 against current main
cjagwani 4c1c55b
merge(main): update #7739 to latest main
cjagwani 829b9a3
test(onboard): convert complete CRLF fixtures
cjagwani 7920f2a
docs(onboard): record Homebrew fallback retirement
cjagwani 5307aa8
fix(onboard): fail closed on unknown brew list errors
apurvvkumaria 76cb83c
merge(main): update #7739 to latest main
harjothkhara b4b590f
merge(main): refresh Homebrew fallback
apurvvkumaria 181e1bf
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cv 7d258a6
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
apurvvkumaria 47218c5
merge(main): refresh #7739 against current main
harjothkhara f68e951
merge(main): refresh Homebrew fallback
apurvvkumaria a170707
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cv ae595ee
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
apurvvkumaria c6e891b
fix(macos): preserve Homebrew lifecycle authority
prekshivyas 9d0fc9b
docs(macos): align Homebrew lifecycle guidance
apurvvkumaria 02cb63e
merge(main): refresh PR base
apurvvkumaria 792fe8b
docs(macos): clarify trusted Homebrew recovery
apurvvkumaria 7661a0e
fix(installer): require Homebrew formula trust support
apurvvkumaria ea5878c
merge(main): incorporate current lifecycle fixes
cv a8d7ecc
docs: give runnable Homebrew repair command
cv 32f2e43
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
prekshivyas 84be847
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
prekshivyas 76e2263
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
prekshivyas 787001e
fix(ci): refresh Homebrew installer trust hash
prekshivyas da8dacf
merge(onboard): update #7739 with main
apurvvkumaria ddda77d
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cv File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
71 changes: 71 additions & 0 deletions
71
src/lib/onboard/gateway-host-runtime-homebrew-untrusted-tap.test.ts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,71 @@ | ||
| // SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. | ||
| // SPDX-License-Identifier: Apache-2.0 | ||
|
|
||
| import { afterEach, beforeEach, describe, expect, it, vi } from "vitest"; | ||
|
|
||
| import { createGatewayHostRuntime, type GatewayHostRuntimeDeps } from "./gateway-host-runtime"; | ||
| import type { PortProbeResult } from "./preflight"; | ||
|
|
||
| // Homebrew 6.x refuses to load formulae from taps it has not marked trusted, | ||
| // so `brew info --json=v2 openshell` fails even though the formula is the | ||
| // pinned official one. The refusal reaches the gateway-owner resolution | ||
| // through the real spawnSync path, not an injected seam (#7707). | ||
| vi.mock("node:child_process", async (importOriginal) => { | ||
| const actual = await importOriginal<typeof import("node:child_process")>(); | ||
| return { | ||
| ...actual, | ||
| spawnSync: vi.fn((command: string, args: readonly string[]) => | ||
| command === "brew" && args[0] === "info" | ||
| ? { | ||
| status: 1, | ||
| stderr: | ||
| "Error: Refusing to load formula nvidia/openshell/openshell from untrusted tap nvidia/openshell.", | ||
| stdout: "", | ||
| } | ||
| : { status: 0, stderr: "", stdout: "" }, | ||
| ), | ||
| }; | ||
| }); | ||
|
|
||
| const ORIGINAL_ENV = { ...process.env }; | ||
|
|
||
| beforeEach(() => { | ||
| vi.spyOn(process, "platform", "get").mockReturnValue("darwin"); | ||
| vi.spyOn(console, "warn").mockImplementation(() => {}); | ||
| }); | ||
|
|
||
| afterEach(() => { | ||
| process.env = { ...ORIGINAL_ENV }; | ||
| vi.restoreAllMocks(); | ||
| }); | ||
|
|
||
| function createDeps(): GatewayHostRuntimeDeps { | ||
| return { | ||
| applyOverlayfsAutoFix: () => null, | ||
| checkGatewayPortAvailable: async () => ({ ok: true }) as PortProbeResult, | ||
| gatewayName: () => "nemoclaw", | ||
| gatewayPort: () => 8080, | ||
| getGatewayPortListenerRawScan: () => ({ pids: [], complete: true }), | ||
| getInstalledOpenshellVersion: () => "0.0.85", | ||
| runCaptureOpenshell: () => "healthy", | ||
| runOpenshell: () => ({ status: 0 }), | ||
| resolveOpenShellGatewayBinary: () => null, | ||
| waitForGatewayHttpReady: async () => true, | ||
| }; | ||
| } | ||
|
|
||
| describe("gateway host runtime on Homebrew 6.x untrusted tap", () => { | ||
| it("resolves a standalone owner instead of aborting when brew refuses the pinned tap (#7707)", () => { | ||
| const warn = vi.spyOn(console, "warn").mockImplementation(() => {}); | ||
| const runtime = createGatewayHostRuntime(createDeps()); | ||
|
|
||
| expect(runtime.getGatewayOwner()).toMatchObject({ | ||
| gatewayName: "nemoclaw", | ||
| gatewayPort: 8080, | ||
| mode: "nemoclaw-managed", | ||
| source: "standalone", | ||
| }); | ||
| expect(runtime.getGatewayOwner()).toMatchObject({ source: "standalone" }); | ||
| expect(warn).toHaveBeenCalledTimes(1); | ||
| }); | ||
| }); |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.