Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
385 commits
Select commit Hold shift + click to select a range
0cf5aac
test(onboard): inventory Docker bootstrap sources
ericksoa Aug 1, 2026
b79f034
test(cli): exclude source fixtures from distribution
ericksoa Aug 1, 2026
2984099
fix(onboard): make terminal recovery restart-safe
ericksoa Aug 1, 2026
0aabe5e
merge: refresh managed create on Docker adapter
ericksoa Aug 1, 2026
310ebeb
test(onboard): fence create on restart recovery
ericksoa Aug 1, 2026
b3b96bc
merge: refresh durable transactions on managed create
ericksoa Aug 1, 2026
08e5ca5
fix(images): complete managed image packaging checkpoint
ericksoa Aug 1, 2026
0013772
test(messaging): keep staged channel fixture canonical
ericksoa Aug 1, 2026
4e9c72f
chore(stack): append durable transaction restack
ericksoa Aug 1, 2026
c2d8be9
chore(stack): refresh image runtime on recovery
ericksoa Aug 1, 2026
d41cadf
chore(stack): refresh managed images on image runtime
ericksoa Aug 1, 2026
61aa6d6
merge(stack): refresh clone handoff fixture
ericksoa Aug 1, 2026
4bb2b58
merge(stack): refresh managed clone provider
ericksoa Aug 1, 2026
b596445
merge(stack): refresh Hermes clone broker
ericksoa Aug 1, 2026
e11da6b
merge(stack): refresh bootstrap protocol
ericksoa Aug 1, 2026
889579b
merge(stack): refresh Docker bootstrap adapter
ericksoa Aug 1, 2026
1c32a4d
merge(stack): refresh managed bootstrap create
ericksoa Aug 1, 2026
16f78b4
merge(stack): refresh durable bootstrap transactions
ericksoa Aug 1, 2026
32becd2
Merge commit '16f78b4355816690f9d8516e04bea8e33a81c8f0' into local/pr…
ericksoa Aug 1, 2026
6db21c3
feat(runtime): add dormant Podman CPU lifecycle
ericksoa Aug 1, 2026
dba161c
Merge commit '32becd295a167d8ebdf86739580b3ee5582b9968' into local/pr…
ericksoa Aug 1, 2026
7456a5d
refactor(onboard): use local no-proxy helper directly
ericksoa Aug 1, 2026
e0524dc
merge(stack): refresh managed image publication
ericksoa Aug 1, 2026
39b034d
feat(runtime): add durable Podman watcher lease
ericksoa Aug 1, 2026
a2e5e80
test(runtime): keep Podman fixtures branch-free
ericksoa Aug 1, 2026
5ac0774
fix(images): keep managed runtime bundle dependency-free
ericksoa Aug 1, 2026
2054840
docs(runtime): record Podman watcher authority
ericksoa Aug 1, 2026
957bfa0
merge(stack): refresh managed image publication
ericksoa Aug 1, 2026
f860304
feat(runtime): reserve Podman bootstrap command scope
ericksoa Aug 1, 2026
b71e9c8
feat(runtime): inspect exact Podman held workload
ericksoa Aug 1, 2026
3b53005
fix(runtime): harden Podman endpoint authority
ericksoa Aug 1, 2026
ff914c7
fix(runtime): acquire Podman watcher lease atomically
ericksoa Aug 1, 2026
e97ecce
merge(stack): refresh managed workload rebuild parity
ericksoa Aug 1, 2026
cbcf8ef
test(runtime): cover Podman lifecycle retries
ericksoa Aug 1, 2026
14a90c5
fix(runtime): bound Podman inspect strings
ericksoa Aug 1, 2026
498cd2f
docs(runtime): name watcher process identity
ericksoa Aug 1, 2026
6b2c464
merge(stack): refresh managed snapshot parity
ericksoa Aug 1, 2026
91c807c
merge(stack): refresh managed clone handoff contract
ericksoa Aug 1, 2026
8ca5867
merge(stack): refresh managed clone provider transaction
ericksoa Aug 1, 2026
2faa95d
merge(stack): refresh Hermes managed clone broker
ericksoa Aug 1, 2026
e90af8b
fix(images): align managed image CI contracts
ericksoa Aug 1, 2026
fc9ff91
merge(stack): refresh managed bootstrap protocol
ericksoa Aug 1, 2026
0d3442e
merge(stack): refresh Docker managed bootstrap adapter
ericksoa Aug 1, 2026
cd65972
merge(stack): refresh managed bootstrap provider create
ericksoa Aug 1, 2026
f72b165
merge(stack): refresh durable bootstrap transactions
ericksoa Aug 1, 2026
84c849b
test(mcp): bound subprocess status checks
ericksoa Aug 1, 2026
0be111d
merge(stack): refresh managed bootstrap recovery
ericksoa Aug 1, 2026
d892b4c
test(runtime): keep watcher lease fixture linear
ericksoa Aug 1, 2026
16ba43b
merge(stack): refresh managed bootstrap image runtime
ericksoa Aug 1, 2026
32e0259
chore(stack): refresh managed image publication parent
ericksoa Aug 1, 2026
26683aa
feat(runtime): add durable Podman bootstrap journal
ericksoa Aug 1, 2026
9ec4f8d
merge(stack): refresh Podman bootstrap authority
ericksoa Aug 1, 2026
26eeb21
merge(stack): refresh Podman command adapter
ericksoa Aug 1, 2026
ffab808
merge(stack): refresh Podman bootstrap authority
ericksoa Aug 1, 2026
77166bc
test(runtime): bind held workload engine authority
ericksoa Aug 1, 2026
f33a363
feat(runtime): persist container engine authority
ericksoa Aug 1, 2026
907b42b
merge(stack): refresh persisted engine authority
ericksoa Aug 1, 2026
86e5e99
merge(stack): retain Podman bootstrap authority
ericksoa Aug 1, 2026
a602f82
merge(stack): refresh persisted engine authority on journal
ericksoa Aug 1, 2026
90ac8f1
feat(runtime): prepare exact Podman bootstrap replacement
ericksoa Aug 1, 2026
39c89b5
feat(runtime): stage Podman image bootstrap
ericksoa Aug 1, 2026
1c1cd2a
test(runtime): inventory Podman bootstrap sources
ericksoa Aug 1, 2026
2a0ff40
test(runtime): include Podman providers in source guard
ericksoa Aug 1, 2026
f89f61b
merge(stack): refresh Podman command adapter
ericksoa Aug 1, 2026
54dad99
test(runtime): verify exact Podman bootstrap rollback
ericksoa Aug 1, 2026
0ca37a2
merge(stack): refresh Podman bootstrap authority
ericksoa Aug 1, 2026
ea52d25
style(runtime): format Podman bootstrap rollback tests
ericksoa Aug 1, 2026
99c4ef2
test(runtime): normalize copied receipt modes
ericksoa Aug 1, 2026
55eb8bb
docs(runtime): record Podman bootstrap rollback contract
ericksoa Aug 1, 2026
3231d9f
merge(stack): refresh managed image publication
ericksoa Aug 1, 2026
d7eb1f5
merge(stack): refresh Podman command adapter
ericksoa Aug 1, 2026
2250c7f
feat(runtime): own Podman bootstrap state volume
ericksoa Aug 1, 2026
b600cb8
merge(stack): refresh repaired Podman bootstrap authority
ericksoa Aug 1, 2026
ca6bd6f
docs(runtime): record Podman bootstrap state ownership
ericksoa Aug 1, 2026
3d2efa1
fix(runtime): retain exact state-volume expectation
ericksoa Aug 1, 2026
9231122
feat(runtime): persist lifecycle engine recovery
ericksoa Aug 1, 2026
4e56aa3
merge(stack): refresh Podman bootstrap journal
ericksoa Aug 1, 2026
e7558bc
fix(runtime): harden lifecycle ledger recovery
ericksoa Aug 1, 2026
c004920
test(runtime): keep Podman harness branches explicit
ericksoa Aug 1, 2026
289287c
test(runtime): keep Podman image transaction fixture linear
ericksoa Aug 1, 2026
a46396a
test(runtime): inventory Podman bootstrap transactions
ericksoa Aug 1, 2026
2550531
fix(runtime): revalidate lifecycle completion
ericksoa Aug 1, 2026
ab65196
merge(stack): refresh Podman bootstrap journal checks
ericksoa Aug 1, 2026
4e18b65
test(runtime): inventory Podman image transaction
ericksoa Aug 1, 2026
c992dd3
fix(runtime): harden Podman bootstrap reconciliation
ericksoa Aug 1, 2026
fd82f60
fix(runtime): bind Podman image bootstrap authority
ericksoa Aug 1, 2026
256e687
fix(runtime): type persisted lifecycle callbacks
ericksoa Aug 1, 2026
377a9ea
test(runtime): discriminate Podman mount parsing
ericksoa Aug 1, 2026
094cea4
fix(runtime): accept omitted Podman shared mount mode
ericksoa Aug 1, 2026
8b5299d
fix(runtime): type lifecycle test capture
ericksoa Aug 1, 2026
dc3a484
docs(runtime): align Podman mount evidence
ericksoa Aug 1, 2026
6ae135a
merge(stack): refresh Podman bootstrap review fixes
ericksoa Aug 1, 2026
005ce53
fix(images): set root before DCode handoff
ericksoa Aug 1, 2026
9283304
merge(stack): append Podman image bootstrap transaction
ericksoa Aug 1, 2026
913c724
docs(runtime): record Podman image transaction boundary
ericksoa Aug 1, 2026
b403f7a
merge(stack): refresh Podman image bootstrap docs
ericksoa Aug 1, 2026
362a70c
chore(stack): refresh managed workload rebuild parity on current main
ericksoa Aug 1, 2026
b2374ee
chore(stack): refresh managed snapshot parity parent
ericksoa Aug 1, 2026
e09ce8a
chore(stack): refresh managed clone handoff parent
ericksoa Aug 1, 2026
aeeb6dd
chore(stack): refresh managed clone provider parent
ericksoa Aug 1, 2026
968c795
chore(stack): refresh Hermes clone broker parent
ericksoa Aug 1, 2026
fb0d7aa
chore(stack): refresh managed bootstrap protocol parent
ericksoa Aug 1, 2026
976771e
chore(stack): refresh Docker bootstrap adapter parent
ericksoa Aug 1, 2026
1978cfa
docs(runtime): clarify persisted engine authority
ericksoa Aug 1, 2026
ff5b16b
chore(stack): refresh managed bootstrap create parent
ericksoa Aug 1, 2026
300338c
merge(stack): restack persisted engine lifecycle
ericksoa Aug 1, 2026
998296e
chore(stack): refresh durable bootstrap transaction parent
ericksoa Aug 1, 2026
3be9d84
chore(stack): refresh managed bootstrap recovery parent
ericksoa Aug 1, 2026
ff7a040
chore(stack): refresh managed bootstrap image runtime parent
ericksoa Aug 1, 2026
e1d380e
chore(stack): refresh managed image publication parent
ericksoa Aug 1, 2026
269de66
test(runtime): avoid persisted authority check-use race
ericksoa Aug 1, 2026
606a482
merge(stack): refresh persisted engine lifecycle base
ericksoa Aug 1, 2026
cfa7cbb
feat(runtime): qualify Podman inference GPUs
ericksoa Aug 1, 2026
8bfea3a
chore(stack): refresh Podman command adapter parent
ericksoa Aug 1, 2026
d6f1cd6
chore(stack): refresh Podman bootstrap authority parent
ericksoa Aug 1, 2026
4b4fcef
chore(stack): refresh Podman bootstrap journal parent
ericksoa Aug 1, 2026
5250328
chore(stack): refresh Podman image transaction parent
ericksoa Aug 1, 2026
ae30b06
chore(stack): refresh persisted engine authority parent
ericksoa Aug 1, 2026
02b7389
merge(stack): refresh persisted engine lifecycle
ericksoa Aug 1, 2026
db3637a
merge(stack): refresh persisted engine lifecycle parent
ericksoa Aug 1, 2026
d11f708
feat(runtime): translate Podman inference commands
ericksoa Aug 1, 2026
1d2a111
merge(stack): refresh persisted engine lifecycle parent
ericksoa Aug 1, 2026
b12db1c
test(runtime): linearize lifecycle harness setup
ericksoa Aug 1, 2026
9d8fee1
feat(runtime): define host-local inference receipts
ericksoa Aug 1, 2026
bff34f9
merge(stack): refresh persisted engine lifecycle parent
ericksoa Aug 1, 2026
ca85ca7
fix(hermes): preserve broker write ownership
ericksoa Aug 1, 2026
8db756d
chore(stack): incorporate Hermes broker review repairs
ericksoa Aug 1, 2026
3e25313
chore(stack): incorporate Hermes broker review repairs
ericksoa Aug 1, 2026
08060dd
chore(stack): incorporate Hermes broker review repairs
ericksoa Aug 1, 2026
eb88cce
merge(stack): refresh Podman inference parent
ericksoa Aug 1, 2026
bcf2ae9
chore(stack): incorporate Hermes broker review repairs
ericksoa Aug 1, 2026
642ff9d
fix(runtime): serialize persisted lifecycle execution
ericksoa Aug 1, 2026
f2a5806
test(onboard): linearize transaction recovery cases
ericksoa Aug 1, 2026
743a2f3
chore(stack): incorporate transaction test repairs
ericksoa Aug 1, 2026
6c23ebd
feat(runtime): bind host-local inference specifications
ericksoa Aug 1, 2026
2c11802
chore(stack): incorporate transaction test repairs
ericksoa Aug 1, 2026
2d55f98
chore(stack): incorporate transaction test repairs
ericksoa Aug 1, 2026
beb5731
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
de70077
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
9cb9e34
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
0f125e0
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
0fde3f9
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
52ecd0b
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
54cc06f
feat(runtime): manage Podman host-local inference
ericksoa Aug 1, 2026
32751f3
merge(stack): refresh persisted engine lifecycle parent
ericksoa Aug 1, 2026
ee6ad30
merge(stack): refresh Podman inference parent
ericksoa Aug 1, 2026
333aab6
merge(stack): refresh host-local inference receipt parent
ericksoa Aug 1, 2026
4c66a17
feat(runtime): expose host-local inference providers
ericksoa Aug 1, 2026
ec453b7
test(runtime): complete provider surface fixture
ericksoa Aug 1, 2026
1add3cc
chore(runtime): format host-local inference slice
ericksoa Aug 1, 2026
d4622df
fix(runtime): reject duplicate Podman CDI inventory
ericksoa Aug 1, 2026
5aaf988
chore(stack): refresh E2E qualification
ericksoa Aug 1, 2026
5472c30
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
faa8610
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
1f4683f
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
fda94da
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
fb1e210
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
e724196
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
03f5a3d
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
a2ae17e
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
baa495a
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
e74e262
merge(stack): refresh persisted engine lifecycle parent
ericksoa Aug 1, 2026
3ef4794
test(runtime): linearize Podman inference harness
ericksoa Aug 1, 2026
f4628d3
merge(stack): refresh Podman GPU translation parent
ericksoa Aug 1, 2026
3485901
merge(stack): refresh host-local inference receipt parent
ericksoa Aug 1, 2026
4b75eb4
refactor(runtime): keep receipt slice domain-only
ericksoa Aug 1, 2026
e2c5a19
merge(stack): narrow host-local inference receipt parent
ericksoa Aug 1, 2026
4b73583
fix(runtime): bind host inference authority exactly
ericksoa Aug 1, 2026
91eec72
feat(runtime): route host-local inference
ericksoa Aug 1, 2026
2f38f47
fix(runtime): bind inference receipt authority
ericksoa Aug 1, 2026
0410dbe
merge(stack): bind host inference parent
ericksoa Aug 1, 2026
3961da6
test(runtime): inventory host-local routing boundary
ericksoa Aug 1, 2026
fdb1136
feat(runtime): persist host-local inference authority
ericksoa Aug 1, 2026
9165574
test(runtime): type host-local route reservation
ericksoa Aug 1, 2026
c2cc2ce
fix(runtime): probe managed inference readiness
ericksoa Aug 2, 2026
c176e0d
merge(stack): restack routing on inference readiness
ericksoa Aug 2, 2026
304d28d
refactor(runtime): narrow durable inference ownership
ericksoa Aug 2, 2026
d791ea3
merge(stack): restack durable inference ownership
ericksoa Aug 2, 2026
81672c7
test(runtime): isolate Podman inference harness
ericksoa Aug 2, 2026
895d0e5
docs(runtime): align inference route terminology
ericksoa Aug 2, 2026
d62c13b
merge(stack): restack routing on test-only harness
ericksoa Aug 2, 2026
b239739
merge(stack): restack durable ownership on review fixes
ericksoa Aug 2, 2026
303387b
fix(runtime): reprove managed inference readiness
ericksoa Aug 2, 2026
38f670e
merge(stack): restack routing on managed readiness
ericksoa Aug 2, 2026
68991cc
test(runtime): carry managed readiness authority
ericksoa Aug 2, 2026
57525d0
merge(stack): restack durable ownership on managed readiness
ericksoa Aug 2, 2026
5dd4ca8
fix(state): validate inference ownership receipts
ericksoa Aug 2, 2026
b588f8b
test(runtime): cover managed route retry
ericksoa Aug 2, 2026
4d05ed7
merge(stack): restack ownership on route retry coverage
ericksoa Aug 2, 2026
ddadc80
test(state): cover explicit inference ownership clear
ericksoa Aug 2, 2026
ddb5feb
fix(state): exclude route ownership from recreate fingerprint
ericksoa Aug 2, 2026
990a5f5
fix(state): preserve reserved inference receipt
ericksoa Aug 2, 2026
14d8f52
fix(runtime): bind held workload namespace
apurvvkumaria Aug 3, 2026
a672a3f
feat(runtime): qualify Podman inference commands (#8059)
ericksoa Aug 3, 2026
9209d31
feat(runtime): define host-local inference receipts (#8060)
ericksoa Aug 3, 2026
8672699
feat(onboard): activate buildless managed workloads
ericksoa Aug 4, 2026
f83d8db
test(onboard): cover managed activation regressions
ericksoa Aug 4, 2026
18de09f
fix(onboard): harden managed activation qualification
ericksoa Aug 4, 2026
b433fc6
fix(ci): refresh live E2E parity mapping
ericksoa Aug 4, 2026
08ab3ff
fix(e2e): isolate legacy lanes from managed activation
ericksoa Aug 4, 2026
0040c91
merge: resolve conflicts with main
github-actions[bot] Aug 5, 2026
01c4a0a
fix(e2e): preserve legacy Dockerfile lanes
ericksoa Aug 5, 2026
3971674
test(e2e): refresh workflow compatibility digest
ericksoa Aug 5, 2026
07bd38c
test(e2e): activate protected managed runtime qualification
ericksoa Aug 5, 2026
15771f8
feat(runtime): add dormant Podman CPU lifecycle
ericksoa Aug 1, 2026
c791fdf
test(runtime): keep Podman fixtures branch-free
ericksoa Aug 1, 2026
6a28014
fix(runtime): harden Podman endpoint authority
ericksoa Aug 1, 2026
ca24013
test(runtime): cover Podman lifecycle retries
ericksoa Aug 1, 2026
aa2909c
test(runtime): include Podman providers in source guard
ericksoa Aug 1, 2026
c3beceb
fix(runtime): adapt Podman boundary to current architecture
ericksoa Aug 5, 2026
b269b4f
test(e2e): prove rootless Podman CPU lifecycle
ericksoa Aug 5, 2026
3d5f58e
fix(e2e): harden Docker shutdown for Podman proof
ericksoa Aug 5, 2026
9d865f8
fix(e2e): remove stale Docker socket after shutdown
ericksoa Aug 5, 2026
b27446e
fix(e2e): preserve legacy workload source coverage
ericksoa Aug 5, 2026
102055c
chore(stack): restack Podman proof on buildless activation
ericksoa Aug 5, 2026
1579e1d
test(e2e): register Podman live proof parity
ericksoa Aug 5, 2026
ca517d1
feat(onboard): gate managed runtime activation
ericksoa Aug 5, 2026
10b3589
merge(stack): refresh Podman proof on gated buildless activation
ericksoa Aug 5, 2026
da4fce1
merge(main): integrate CLI test isolation fixes
ericksoa Aug 5, 2026
e25e216
merge(stack): refresh Podman proof on current buildless base
ericksoa Aug 5, 2026
a254cf1
fix(runtime): bind Podman proof evidence
ericksoa Aug 5, 2026
1d816ab
merge(stack): rebuild Podman bootstrap batch on CPU proof
ericksoa Aug 5, 2026
8af8166
merge(stack): carry exact Podman proof head
ericksoa Aug 5, 2026
b6c404a
merge(stack): rebuild persisted runtime recovery on bootstrap
ericksoa Aug 5, 2026
0fa67eb
feat(runtime): define state mutation contract
jyaunches Aug 4, 2026
f40b6da
fix(runtime): harden state mutation plan validation
jyaunches Aug 4, 2026
085adae
fix(runtime): protect live Podman bootstrap leases
ericksoa Aug 5, 2026
25b2155
test(runtime): keep state mutation guards linear
ericksoa Aug 5, 2026
2247488
merge(stack): carry hardened Podman bootstrap head
ericksoa Aug 5, 2026
a84e56c
merge(stack): rebuild Podman GPU and inference runtime
ericksoa Aug 5, 2026
1539456
merge(stack): integrate host-local inference routing
ericksoa Aug 5, 2026
ee60626
feat(runtime): add dormant Podman managed bootstrap transaction (#8052)
ericksoa Aug 5, 2026
310c988
feat(runtime): add dormant Podman CPU lifecycle proof (#8276)
ericksoa Aug 5, 2026
9e60ef6
merge(stack): absorb qualified bootstrap batch
ericksoa Aug 5, 2026
d5159f4
merge(stack): absorb persisted lifecycle batch
ericksoa Aug 5, 2026
ed6b7e8
merge: resolve conflicts with main
github-actions[bot] Aug 5, 2026
5042e1e
merge: resolve conflicts with main
github-actions[bot] Aug 5, 2026
7490de2
fix(onboard): align composed inference dependencies
ericksoa Aug 5, 2026
7953081
merge(stack): preserve inference dependency fix
ericksoa Aug 5, 2026
ee460c4
merge(stack): reconcile persisted lifecycle with MXC
ericksoa Aug 5, 2026
d46c539
merge(stack): absorb repaired buildless base
ericksoa Aug 5, 2026
f046d6e
merge(stack): reconcile host inference with MXC
ericksoa Aug 5, 2026
c1d6087
docs(runtime): clarify dormant Podman contracts
ericksoa Aug 5, 2026
5d55661
test(runtime): align Podman CDI diagnostic
ericksoa Aug 5, 2026
f4a355f
merge(stack): restack durable inference ownership
ericksoa Aug 5, 2026
c96cf8d
feat(runtime): complete host-local inference lifecycle
ericksoa Aug 5, 2026
e09c1f2
docs(runtime): state cleanup authority contract
ericksoa Aug 5, 2026
4fa744c
fix(runtime): complete destroy failure contract
ericksoa Aug 5, 2026
b3e3dcf
fix(inference): clear stale host-local ownership
prekshivyas Aug 11, 2026
264d427
fix(destroy): retain host-local runtime ownership
prekshivyas Aug 11, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/e2e.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2314,6 +2314,7 @@ jobs:
E2E_DEFAULT_ENABLED: "0"
E2E_JOB: "1"
E2E_TARGET_ID: "managed-image-protected-runtime"
E2E_WORKLOAD_SOURCE: "managed-image"
RELEASE_E2E_ACTIVATION_PATH: ci/protected-managed-image-runtime-activation-v1.json
NEMOCLAW_CLI_BIN: ${{ github.workspace }}/bin/nemoclaw.js
NEMOCLAW_E2E_SHARD: linux-amd64-gpu
Expand Down
232 changes: 232 additions & 0 deletions .github/workflows/podman-cpu-proof.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,232 @@
# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0

name: Runtime / Podman CPU Proof

run-name: "Podman CPU proof PR #${{ github.event.pull_request.number }} head ${{ github.event.pull_request.head.sha }}"

on:
pull_request:
types: [opened, synchronize, reopened]
paths:
- ".github/workflows/podman-cpu-proof.yaml"
- "src/lib/adapters/container-engine.ts"
- "src/lib/adapters/podman/**"
- "src/lib/onboard/runtime-provider/podman*.ts"
- "test/e2e/live/podman-cpu-lifecycle.test.ts"
- "test/e2e/support/podman-cpu-proof-workflow.test.ts"

permissions:
contents: read

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number }}
cancel-in-progress: true

jobs:
podman-cpu-lifecycle:
name: Rootless Podman CPU lifecycle with Docker disabled
runs-on: ubuntu-26.04
timeout-minutes: 30
env:
E2E_ARTIFACT_DIR: ${{ github.workspace }}/e2e-artifacts/podman-cpu-proof
E2E_DEFAULT_ENABLED: "0"
E2E_JOB: "1"
E2E_TARGET_ID: podman-cpu-lifecycle
NEMOCLAW_RUN_LIVE_E2E: "1"
PODMAN_APT_VERSION: "5.7.0+ds2-3build1"
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
ref: ${{ github.event.pull_request.head.sha }}

- name: Set up Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22.19.0
cache: npm

- name: Install locked test dependencies
run: npm ci --ignore-scripts

- name: Install Podman 5 runtime
shell: bash
run: |
set -euo pipefail
sudo apt-get update
sudo apt-get install --yes "podman=$PODMAN_APT_VERSION"
package_version="$(dpkg-query --show --showformat='${Version}' podman)"
version="$(podman --version)"
test "$package_version" = "$PODMAN_APT_VERSION"
test "$version" = "podman version 5.7.0"
printf '### Podman runtime\n\n`%s` (`%s`)\n' "$version" "$package_version" >>"$GITHUB_STEP_SUMMARY"

- name: Install Docker invocation guard
shell: bash
run: |
set -euo pipefail
guard_dir="$RUNNER_TEMP/nemoclaw-podman-cpu-guard"
guard_log="$guard_dir/docker-invocations.log"
install -d -m 0700 "$guard_dir/bin"
: >"$guard_log"
cat >"$guard_dir/bin/docker" <<'DOCKER_GUARD'
#!/usr/bin/env bash
printf '%s\n' "$*" >>"${E2E_DOCKER_GUARD_LOG:?}"
printf 'Docker CLI use is forbidden in the native Podman CPU proof.\n' >&2
exit 97
DOCKER_GUARD
chmod 0700 "$guard_dir/bin/docker"
{
printf 'DOCKER_API_VERSION=\n'
printf 'DOCKER_CERT_PATH=\n'
printf 'DOCKER_CONFIG=\n'
printf 'DOCKER_CONTEXT=\n'
printf 'DOCKER_HOST=\n'
printf 'DOCKER_TLS_VERIFY=\n'
printf 'E2E_DOCKER_GUARD_BIN=%s\n' "$guard_dir/bin/docker"
printf 'E2E_DOCKER_GUARD_LOG=%s\n' "$guard_log"
printf 'PATH=%s:%s\n' "$guard_dir/bin" "$PATH"
} >>"$GITHUB_ENV"

- name: Disable Docker daemon and socket
shell: bash
run: |
set -euo pipefail
install -d -m 0700 "$E2E_ARTIFACT_DIR"
sudo systemctl stop docker.service docker.socket || true
sudo systemctl mask --runtime docker.service docker.socket || true
sudo pkill -TERM -x dockerd 2>/dev/null || true
for attempt in $(seq 1 20); do
if ! pgrep -x dockerd >/dev/null; then
break
fi
sleep 1
done
if pgrep -x dockerd >/dev/null; then
echo "::error::dockerd remained active after Docker shutdown" >&2
exit 1
fi
sudo rm -f /var/run/docker.sock
if systemctl is-active --quiet docker.service; then
echo "::error::docker.service remained active after Docker shutdown" >&2
exit 1
fi
if systemctl is-active --quiet docker.socket; then
echo "::error::docker.socket remained active after Docker shutdown" >&2
exit 1
fi
if [ -S /var/run/docker.sock ]; then
echo "::error::Docker socket remained available after Docker shutdown" >&2
exit 1
fi
docker_candidate="$(command -v docker || true)"
if [ "$docker_candidate" != "$E2E_DOCKER_GUARD_BIN" ]; then
echo "::error::Docker command resolution escaped the invocation guard" >&2
exit 1
fi
jq -n \
--arg dockerCandidate "$docker_candidate" \
'{
schemaVersion: 1,
dockerServiceActive: false,
dockerSocketActive: false,
dockerDaemonActive: false,
dockerSocketPresent: false,
dockerCandidate: $dockerCandidate
}' >"$E2E_ARTIFACT_DIR/docker-absence-boundary.json"

- name: Start exact rootless Podman API socket
shell: bash
run: |
set -euo pipefail
umask 077
uid="$(id -u)"
runtime_dir="/run/user/$uid"
socket_path="$runtime_dir/podman/podman.sock"
if [ ! -d "$runtime_dir" ]; then
sudo install -d -o "$uid" -g "$(id -g)" -m 0700 "$runtime_dir"
fi
install -d -m 0700 "$runtime_dir" "$runtime_dir/podman" "$E2E_ARTIFACT_DIR"
service_log="$E2E_ARTIFACT_DIR/podman-system-service.log"
podman system service --time=0 "unix://$socket_path" >"$service_log" 2>&1 &
service_pid="$!"
for attempt in $(seq 1 30); do
if podman --url "unix://$socket_path" info --format json \
>"$E2E_ARTIFACT_DIR/podman-info.json" 2>>"$service_log"; then
break
fi
test "$attempt" -lt 30
sleep 1
done
test -S "$socket_path"
jq -e '
(.host.security.rootless // .Host.Security.Rootless) == true
and ((.host.cgroupVersion // .Host.CgroupVersion) | ascii_downcase) == "v2"
' "$E2E_ARTIFACT_DIR/podman-info.json" >/dev/null
{
printf 'E2E_PODMAN_SERVICE_PID=%s\n' "$service_pid"
printf 'E2E_PODMAN_SOCKET=%s\n' "$socket_path"
printf 'XDG_RUNTIME_DIR=%s\n' "$runtime_dir"
} >>"$GITHUB_ENV"

- name: Create exact managed lifecycle fixtures
shell: bash
run: |
set -euo pipefail
endpoint="unix://$E2E_PODMAN_SOCKET"
image_ref="docker.io/library/alpine:3.21.3"
podman --url "$endpoint" pull --quiet "$image_ref"
image_id="$(podman --url "$endpoint" image inspect --format '{{.Id}}' "$image_ref")"
test -n "$image_id"
for agent in openclaw hermes langchain-deepagents-code; do
sandbox_name="podman-$agent"
podman --url "$endpoint" create \
--name "openshell-sandbox-$sandbox_name" \
--label "openshell.managed=true" \
--label "openshell.sandbox-id=e2e-$agent" \
--label "openshell.sandbox-name=$sandbox_name" \
--label "openshell.sandbox-namespace=default" \
"$image_id" \
/bin/sh -c 'trap "exit 0" TERM INT; while :; do sleep 60; done'
done

- name: Prove native Podman preflight and all-agent CPU lifecycle
run: npx vitest run --project e2e-live test/e2e/live/podman-cpu-lifecycle.test.ts

- name: Verify Docker stayed unavailable
if: always()
shell: bash
run: |
set -euo pipefail
test -f "$E2E_DOCKER_GUARD_LOG"
test ! -s "$E2E_DOCKER_GUARD_LOG"
test "$(command -v docker)" = "$E2E_DOCKER_GUARD_BIN"
! systemctl is-active --quiet docker.service
! systemctl is-active --quiet docker.socket
test ! -S /var/run/docker.sock

- name: Clean up rootless Podman fixtures
if: always()
shell: bash
run: |
set -euo pipefail
endpoint="unix://${E2E_PODMAN_SOCKET:-/run/user/$(id -u)/podman/podman.sock}"
for agent in openclaw hermes langchain-deepagents-code; do
podman --url "$endpoint" rm --force "openshell-sandbox-podman-$agent" || true
done
service_pid="${E2E_PODMAN_SERVICE_PID:-}"
if [[ "$service_pid" =~ ^[1-9][0-9]*$ ]]; then
kill "$service_pid" 2>/dev/null || true
wait "$service_pid" 2>/dev/null || true
fi

- name: Upload Podman CPU proof artifacts
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: podman-cpu-proof-${{ github.event.pull_request.number }}-${{ github.event.pull_request.head.sha }}
path: e2e-artifacts/podman-cpu-proof
if-no-files-found: error
retention-days: 7
4 changes: 2 additions & 2 deletions ci/protected-managed-image-runtime-activation-v1.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"agents": ["openclaw", "hermes", "langchain-deepagents-code"],
"contractVersion": 1,
"jobId": "managed-image-protected-runtime",
"platform": "linux/amd64",
"providers": ["ollama", "nim", "vllm"]
"providers": ["ollama", "nim", "vllm"],
"agents": ["openclaw", "hermes", "langchain-deepagents-code"]
}
9 changes: 7 additions & 2 deletions ci/source-shape-test-budget.json
Original file line number Diff line number Diff line change
Expand Up @@ -266,6 +266,11 @@
"test": "routes only the measured heavy lanes on trusted main (#7145)",
"category": "security"
},
{
"file": "test/e2e/support/podman-cpu-proof-workflow.test.ts",
"test": "runs as a credential-free exact-head PR workflow",
"category": "security"
},
{
"file": "test/e2e/support/trusted-hermes-swap-workflow-boundary.test.ts",
"test": "keeps the fixed privileged program before candidate checkout in every protected job (#7145)",
Expand Down Expand Up @@ -558,12 +563,12 @@
},
{
"file": "test/runtime-provider-source-shape.test.ts",
"test": "keeps production activation paths disconnected from driver bootstrap adapters",
"test": "keeps central activation paths disconnected from driver bootstrap adapters",
"category": "security"
},
{
"file": "test/runtime-provider-source-shape.test.ts",
"test": "keeps registered providers bootstrap-unsupported",
"test": "composes Docker bootstrap locally while keeping Kubernetes unsupported",
"category": "security"
},
{
Expand Down
1 change: 1 addition & 0 deletions scripts/checks/run-managed-image-openshell-e2e.ts
Original file line number Diff line number Diff line change
Expand Up @@ -804,6 +804,7 @@ async function run(input: Inputs): Promise<void> {
terminalAgent: input.agent === "langchain-deepagents-code",
managedBootstrap: {
bootstrapIdentity: launch.managedBootstrapIdentity,
stateRoot: stateDir,
runtimeProvider,
authorityStore: createProtectedAuthorityStore(stateDir),
request: launch.managedStartupRootApplyRequest,
Expand Down
Loading
Loading