fix(skills): preserve superseded PR attribution - #7974
Conversation
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
📝 WalkthroughWalkthroughSuperseded PR workflows now separate relationship detection from transferred-work verification. Attribution policy checks are required before ranking, merging, or closing a superseded PR. Tests validate authorship, co-authorship, DCO, parser orientation, comparator reruns, and closure requirements. ChangesSuperseded PR attribution
Estimated code review effort: 3 (Moderate) | ~20 minutes Suggested labels: Suggested reviewers: Sequence Diagram(s)sequenceDiagram
participant PRFinder
participant SupersessionParser
participant Comparator
participant AttributionPolicy
PRFinder->>SupersessionParser: Parse supersession statements
SupersessionParser-->>PRFinder: Return normalized PR relationships
PRFinder->>Comparator: Compare commits, diffs, and scope
Comparator->>AttributionPolicy: Verify transferred contribution attribution
AttributionPolicy-->>Comparator: Return verification result
Comparator-->>PRFinder: Return winner or no clear winner
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit 52fdd4a in the TypeScript / code-coverage/cliThe overall coverage in commit 52fdd4a in the Show a code coverage summary of the most impacted files.
Updated |
PR Review Advisor — No blocking findings reportedAdvisor assessment: No blocking advisor findings reported Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: None This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.agents/skills/nemoclaw-maintainer-find-review-pr/SKILL.md:
- Line 102: Update the closure guidance around the `#1392/`#1416 comparison to
require completed transfer, verification of updated commits and CI, and a rerun
of the comparator before recommending source closure. Preserve the existing
full-scope and contributor-attribution checks, and make closure conditional on
the post-transfer comparison succeeding.
In @.agents/skills/nemoclaw-maintainer-pr-comparator/SKILL.md:
- Around line 62-70: Use one canonical supersession pattern set across the
workflow, matching parse-supersession.sh and consistently including “follow-up
to” and “closes in favor of”. Update the documented patterns in
.agents/skills/nemoclaw-maintainer-pr-comparator/SKILL.md lines 62-70 and apply
the same set in .agents/skills/nemoclaw-maintainer-find-review-pr/SKILL.md lines
71-77 before commit/diff and attribution checks.
In @.agents/skills/nemoclaw-maintainer-pr-comparator/templates/verdict.md:
- Around line 58-68: Update the transfer workflow in the numbered action list to
explicitly verify the source PR’s Signed-off-by declaration, preserve the
replacement author’s DCO declaration when reconstructing commits, and reject
copying another contributor’s DCO sign-off. Also require confirming every
replacement commit is GitHub-verified before rerunning the comparator and
proceeding with closure; keep the existing transfer, attribution, CI, and
comparator steps intact.
In `@test/maintainer-skills-policy.test.ts`:
- Around line 353-361: Strengthen the assertions in the verdict-order test
around the existing transfer, comparator rerun, merge, and source-PR closure
text. Capture each phrase’s index and assert the complete sequence: transfer
first, comparator verification/rerun next, merge only afterward, and closure
after the new verdict; keep the test focused on the public policy output rather
than implementation details.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 5ee7b29a-f0c4-47ed-a31d-facb321e9238
📒 Files selected for processing (6)
.agents/skills/nemoclaw-maintainer-find-review-pr/SKILL.md.agents/skills/nemoclaw-maintainer-policies/references/workflow-policy.md.agents/skills/nemoclaw-maintainer-pr-comparator/SKILL.md.agents/skills/nemoclaw-maintainer-pr-comparator/templates/verdict.md.agents/skills/nemoclaw-maintainer-pr-comparator/tiebreakers.mdtest/maintainer-skills-policy.test.ts
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary Adds the canonical dated changelog entry for `v0.0.100` so the maintainer release plan can verify the pre-tag documentation prerequisite. The entry summarizes the user-facing changes merged since `v0.0.99` and links to the relevant guides. ## Changes - Add `docs/changelog/2026-07-31.mdx` with the exact `## v0.0.100` heading. - Cover restored OpenClaw pairing, transactional replacement, Deep Agents Code, onboarding recovery, lifecycle cleanup, Hermes builds, host provenance, documentation, and trusted E2E evidence. - Distinguish active Docker and Kubernetes runtime-bundle enforcement from the still-inactive managed shared-state transaction foundation. ## Source Coverage The release entry maps the doc-impacting merged PRs in the `v0.0.99..main` release range to `docs/changelog/2026-07-31.mdx`: #8021, #8024, #7973, #8028, #7947, #7788, #7884, #8023, #7969, #8020, #7989, #8000, #7907, #7942, #7567, #8013, #7955, #8017, #8014, #8015, #7629, #7644, #7821, #7971, and #7991. PR #7974 was reviewed after the final rebase and excluded because it changes internal maintainer-skill attribution policy and tests only; it does not change a user-facing product or documentation surface. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: the changelog contract test validates the dated entry, version heading, SPDX form, and route constraints. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: `docs/changelog/2026-07-31.mdx`; exact-head review passed for `6093f44f`; writing rules and documentation style reviewed; `npx vitest run test/changelog-docs.test.ts` passed 6/6; `npm run docs` passed with zero Fern errors and two generic Fern upgrade notices. - Agent: Codex Desktop <!-- docs-review-head-sha: 6093f44 --> <!-- docs-review-agents-blob-sha: 3dd7c24 --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable; no DGX Station host script changed. - Station profile/scenario: Not applicable. - Result: Not applicable. - Supporting evidence: Not applicable. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run validate:pr` passed after refreshing `origin/main` when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: `npx vitest run test/changelog-docs.test.ts` passed 6/6 at `6093f44f`. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to a dated prose-only release entry. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — validation passed with zero errors; Fern emitted two generic upgrade notices. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — the changelog entry has the required parser-safe MDX SPDX header; dated changelog entries intentionally do not use page frontmatter. --- Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added release notes for v0.0.100. * Documented improvements to restore pairing, sandbox replacement, onboarding recovery, lifecycle cleanup, runtime handling, build support, host readiness, and end-to-end validation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
Summary
The #6684/#6689 supersession exposed that the maintainer workflow could select a replacement and recommend closing its source without checking whether transferred work retained machine-readable contributor attribution.
This change treats supersession as relationship evidence, requires exact source-commit authorship or co-authorship before selection and closure, and preserves the existing authorization boundaries.
Changes
independent,transferred, orunclear, and leave the winner unset when attribution evidence is missing.render-verdict.pyandvalidation/backtest.mdunchanged because this is a reviewer workflow contract, not a renderer gate.Type of Change
Quality Gates
Documentation Writer Review
no-docs-neededdocs/change is needed because the change affects only maintainer-agent behavior. The final review found no issues; the focused contract passed 18/18, and repository-managed shfmt and ShellCheck passed.DGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run validate:prpassed after refreshingorigin/mainwhen hooks were skipped or unavailablenpx vitest run --project integration test/maintainer-skills-policy.test.ts: 18/18 passed;npx vitest run --project integration test/skills-frontmatter.test.ts: 29/29 passed; repository-managed shfmt and ShellCheck: passed;npm run checks:repository: passed.npm testfor broad runtime/test-harness changes;npm run checkfor repo-wide validation/coverage changes — command/result: Not applicable to scoped maintainer skill guidance and its source-contract test.npm run docsbuilds without warnings (doc changes only)Signed-off-by: Carlos Villela cvillela@nvidia.com
Summary by CodeRabbit
Documentation
Bug Fixes
Tests