Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
573 commits
Select commit Hold shift + click to select a range
c23f5c3
fix(onboard): release route reservation on reuse
prekshivyas Aug 23, 2026
f0fe66a
test(e2e): satisfy loop growth guardrail
prekshivyas Aug 23, 2026
25056ce
Merge origin/main into feat/b3-e-buildless-onboarding-9140
prekshivyas Aug 23, 2026
d47032f
fix(runtime): align provider compatibility boundaries
ericksoa Aug 23, 2026
bc4e68c
fix(onboard): fail closed on GPU cleanup identity
prekshivyas Aug 23, 2026
3a39d28
Merge remote-tracking branch 'origin/feat/b3-e-buildless-onboarding-9…
ericksoa Aug 23, 2026
784c5c8
test(runtime): preserve bootstrap growth guard
ericksoa Aug 23, 2026
86218a5
test(ci): satisfy static guardrails
prekshivyas Aug 23, 2026
6116bfe
Merge remote-tracking branch 'origin/feat/b3-e-buildless-onboarding-9…
ericksoa Aug 23, 2026
60269b2
fix(ci): preserve trusted supervisor runtime template
ericksoa Aug 23, 2026
b847d40
fix(onboard): align managed fallback guidance
prekshivyas Aug 23, 2026
c380fc0
Merge origin/main into feat/b3-e-buildless-onboarding-9140
prekshivyas Aug 23, 2026
56ba1e0
Merge remote-tracking branch 'origin/feat/b3-e-buildless-onboarding-9…
ericksoa Aug 23, 2026
0943a7d
fix(hermes): admit reviewed startup test source
prekshivyas Aug 23, 2026
71c89c9
Merge remote-tracking branch 'origin/feat/b3-e-buildless-onboarding-9…
ericksoa Aug 23, 2026
d7d1295
fix(ci): align provider fixture and cache growth blobs
ericksoa Aug 23, 2026
b02e83a
fix(ci): reuse parsed growth guard sources
ericksoa Aug 23, 2026
c2d6d42
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 23, 2026
22d5609
test(podman): use current NVIDIA platform identity
ericksoa Aug 23, 2026
79a621a
feat(e2e): qualify managed Docker and Podman runtimes
ericksoa Aug 24, 2026
29f1463
ci(e2e): pin native Podman setup to exact commit
ericksoa Aug 24, 2026
7d44190
fix(e2e): satisfy managed runtime contract typing
ericksoa Aug 24, 2026
d9ed853
chore(runtime): refresh reviewed managed startup bundle
ericksoa Aug 24, 2026
e585484
test(e2e): refresh managed runtime provenance pins
ericksoa Aug 24, 2026
f2c8181
test(e2e): align gateway cleanup provider contract
ericksoa Aug 24, 2026
9a91ec8
test(e2e): exercise provider-neutral DNS restore
ericksoa Aug 24, 2026
f623163
fix(installer): respect native Podman runtime
ericksoa Aug 24, 2026
3ced48d
test(e2e): qualify Podman security posture
ericksoa Aug 24, 2026
b1b9024
test(e2e): reuse unchanged managed images
ericksoa Aug 24, 2026
e821f38
fix(e2e): validate reuse plumbing as non-image
ericksoa Aug 24, 2026
1777f94
fix(e2e): forward managed image publication revision
ericksoa Aug 24, 2026
b7ac017
fix(e2e): restore managed image catalog authority
ericksoa Aug 24, 2026
5661aa0
ci(e2e): pin catalog-aware artifact restore
ericksoa Aug 24, 2026
be61e2a
fix(podman): preserve managed workspace ownership
ericksoa Aug 24, 2026
8700f17
fix(e2e): reuse images for Podman host changes
ericksoa Aug 24, 2026
dffd242
fix(e2e): restore catalog-aware standard profile
ericksoa Aug 24, 2026
f751e46
fix(podman): preserve same-namespace gateway recovery
ericksoa Aug 24, 2026
e57b223
fix(podman): surface bounded bootstrap state failures
ericksoa Aug 24, 2026
917b332
fix(podman): preserve gateway recovery diagnostics
ericksoa Aug 24, 2026
ff025bf
fix(podman): expose managed startup failure stages
ericksoa Aug 24, 2026
ff5f30d
Merge branch 'main' into feat/b4-h-podman-activation-9145
cv Aug 24, 2026
988a4dc
Merge branch 'main' into feat/b4-h-podman-activation-9145
cv Aug 24, 2026
47eb48d
Merge branch 'main' into feat/b4-h-podman-activation-9145
cv Aug 24, 2026
4e50df5
fix(e2e): classify pi qualification runtime
ericksoa Aug 24, 2026
929e100
fix(podman): preserve managed startup authority
ericksoa Aug 24, 2026
21a9b67
fix(e2e): reuse images for Podman host orchestration
ericksoa Aug 24, 2026
ec0aa95
fix(podman): surface managed startup refusal
ericksoa Aug 24, 2026
277f900
Merge branch 'main' into feat/b4-h-podman-activation-9145
cv Aug 24, 2026
1222804
fix(e2e): reuse host-only onboarding changes
ericksoa Aug 24, 2026
b9462a9
fix(podman): pin bootstrap failure log reads
ericksoa Aug 24, 2026
237f709
fix(e2e): preserve candidate build identity
ericksoa Aug 24, 2026
c8370d4
Merge branch 'main' into feat/b4-h-podman-activation-9145
cv Aug 24, 2026
7aa6d11
fix(podman): retain managed bootstrap capabilities
ericksoa Aug 24, 2026
fbaf5bd
fix(e2e): use provider-neutral podman fixtures
ericksoa Aug 24, 2026
0300349
fix(runtime): route stopped backups through providers
ericksoa Aug 24, 2026
aedf5b1
fix(e2e): reuse images for provider maintenance
ericksoa Aug 24, 2026
e8fcf0c
fix(podman): retain bootstrap ownership capabilities
ericksoa Aug 24, 2026
44808c8
fix(e2e): route fake services across runtimes
ericksoa Aug 24, 2026
8f9b0aa
fix(podman): retain bootstrap identity capabilities
ericksoa Aug 24, 2026
fff1180
fix(e2e): align provider-only placeholder checks
ericksoa Aug 24, 2026
a72d1c1
fix(podman): preserve bootstrap exit diagnostics
ericksoa Aug 24, 2026
da11546
fix(e2e): preserve valid provider transitions
ericksoa Aug 24, 2026
07e0592
fix(e2e): bind managed credential fixtures
ericksoa Aug 24, 2026
46de71f
fix(e2e): reuse images for MCP diagnostics
ericksoa Aug 24, 2026
19d229d
fix(podman): preserve managed workspace authority
ericksoa Aug 24, 2026
64b7195
fix(e2e): reassert fixture provider attachments
ericksoa Aug 24, 2026
2799efb
fix(podman): preserve gateway process across bootstrap
ericksoa Aug 24, 2026
8b61c52
fix(e2e): rebind mutated fixture providers
ericksoa Aug 24, 2026
56a1f35
fix(e2e): use provider sandbox host address
ericksoa Aug 24, 2026
91ca880
fix(e2e): refresh Hermes before MCP discovery
ericksoa Aug 24, 2026
6d538a5
fix(podman): wait for post-cutover readiness
ericksoa Aug 24, 2026
1c50286
fix(podman): align runtime E2E contracts
ericksoa Aug 24, 2026
51fc69f
fix(e2e): relay trusted-private MCP through runtime network
ericksoa Aug 24, 2026
686a42b
fix(e2e): resolve managed runtime failure domains
ericksoa Aug 24, 2026
6217b3e
merge(main): refresh Podman qualification base
ericksoa Aug 24, 2026
0ce1608
fix(ci): align Podman matrix qualification contracts
ericksoa Aug 24, 2026
e8aec3f
Merge branch 'main' into feat/b4-h-podman-activation-9145
cv Aug 24, 2026
249c334
fix(ci): use public PR metadata for branch E2E
ericksoa Aug 24, 2026
2294b03
merge(main): refresh branch E2E controller base
ericksoa Aug 24, 2026
b4d5ba4
test: repair grouped integration paths
jyaunches Aug 24, 2026
4c6c89a
fix(runtime): resolve shared managed E2E failures
ericksoa Aug 25, 2026
6704947
Merge branch 'main' into codex/10160-source-shape-unblock
prekshivyas Aug 25, 2026
cf250ea
test: repair latest grouped import paths
cjagwani Aug 25, 2026
7a39b99
docs(security): remove grouped-path merge markers
prekshivyas Aug 25, 2026
8bf0915
fix(hermes): sync grouped-path integrity hash
cjagwani Aug 25, 2026
8af7234
fix(test): finish grouped path repair
rsliter Aug 25, 2026
2d91253
fix(test): remove stale coverage imports
prekshivyas Aug 25, 2026
d7a98a0
fix(hermes): sync profile policy integrity hash
prekshivyas Aug 25, 2026
aa6b959
Merge remote-tracking branch 'origin/pr-10172' into feat/b4-h-podman-…
ericksoa Aug 25, 2026
f8c7f06
fix(images): sync Hermes validator integrity pin
ericksoa Aug 25, 2026
c2e31e1
fix(e2e): converge native Podman runtime contracts
ericksoa Aug 25, 2026
39a9f26
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 25, 2026
9950ed6
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 25, 2026
887b35e
fix(e2e): converge native Podman lifecycle
ericksoa Aug 25, 2026
1ef7071
fix(test): align exact-current CI contracts
ericksoa Aug 25, 2026
d82eba2
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 25, 2026
96b05e9
fix(test): bound growth analysis runtime
ericksoa Aug 25, 2026
c8eabac
fix(e2e): close remaining managed runtime regressions
ericksoa Aug 25, 2026
592ccbf
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 25, 2026
29b6ca6
fix(onboard): isolate portable pairing identity
ericksoa Aug 25, 2026
67e70f2
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 25, 2026
efe66ac
test(inference): cover combined route lock
ericksoa Aug 25, 2026
30d34c4
fix(onboard): keep dashboard recovery gateway scoped
ericksoa Aug 25, 2026
2164956
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 25, 2026
c4fe40d
fix(podman): accept read-only image storage binds
ericksoa Aug 25, 2026
35864fb
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 25, 2026
2bcfc42
fix(podman): normalize live image mount identity
ericksoa Aug 25, 2026
6c0c346
test(e2e): reuse images for Podman runtime fixes
ericksoa Aug 25, 2026
fb84cee
fix(podman): match image overlay inspect flags
ericksoa Aug 25, 2026
86764cb
fix(e2e): avoid installation rate limit for PR catalogs
ericksoa Aug 25, 2026
235250c
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 25, 2026
d42bdf1
fix(e2e): settle managed runtime evidence
ericksoa Aug 25, 2026
37a817e
test(messaging): consolidate applier fixtures
ericksoa Aug 25, 2026
b38239a
fix(e2e): filter Hermes GPU runtime rows
ericksoa Aug 25, 2026
bf1b086
fix(e2e): use canonical Hermes GPU sandbox names
ericksoa Aug 25, 2026
f525f74
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 25, 2026
c29f851
fix(runtime): close native Podman landing blockers
ericksoa Aug 25, 2026
7e2c5d1
test(e2e): enforce pre-candidate toolchain staging
ericksoa Aug 25, 2026
b10ac5d
fix(podman): use executable path for root preparation
ericksoa Aug 25, 2026
b28e9d9
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 26, 2026
cf616d6
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 26, 2026
79423c1
chore(ci): retrigger exact managed-image publication
ericksoa Aug 26, 2026
ad51d54
chore(ci): preserve managed-image reuse boundary
ericksoa Aug 26, 2026
f3fc6a0
fix(podman): close remaining runtime regressions
ericksoa Aug 27, 2026
ae1d2f8
fix(e2e): reuse host-only process recovery images
ericksoa Aug 27, 2026
87a9dbd
fix(onboard): restore messaging runtime identity
ericksoa Aug 27, 2026
8c264d1
fix(e2e): reuse finalization-only image cohort
ericksoa Aug 27, 2026
d402fd2
fix(messaging): republish stored credentials after policy
ericksoa Aug 27, 2026
228fb51
fix(messaging): refresh attached provider snapshot
ericksoa Aug 27, 2026
e655bce
fix(messaging): refresh credential attachment after policy
ericksoa Aug 27, 2026
956390f
fix(messaging): accept current credential aliases
ericksoa Aug 27, 2026
73f499e
fix(messaging): preserve endpointless credential custody
ericksoa Aug 27, 2026
5797585
merge(main): integrate current runtime and E2E fixes
ericksoa Aug 28, 2026
171df46
ci(images): allow exact branch publication dispatch
ericksoa Aug 28, 2026
04161c1
ci(images): trigger PR qualification for base workflow changes
ericksoa Aug 28, 2026
b5300ce
merge(main): integrate latest image and lifecycle fixes
ericksoa Aug 28, 2026
8b1608e
test(ci): align merged runtime contracts
ericksoa Aug 28, 2026
332820e
ci(e2e): reuse images across test budget changes
ericksoa Aug 28, 2026
d63e1f9
ci(e2e): reuse images across source-co-located tests
ericksoa Aug 28, 2026
3c6bb9c
ci(e2e): expose exact PR managed image catalog
ericksoa Aug 28, 2026
1df9a22
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 28, 2026
08c6b29
test(e2e): repair podman qualification assertions
ericksoa Aug 28, 2026
4ac6deb
fix(podman): preserve provider and status authority
ericksoa Aug 28, 2026
7bbcf34
test(e2e): reuse images for host status fixes
ericksoa Aug 28, 2026
582a1d0
test(e2e): restore raw policy receipt authority
ericksoa Aug 28, 2026
b682655
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 28, 2026
7d41bbd
test(e2e): reuse images for host inference fixes
ericksoa Aug 28, 2026
e96c923
fix(shields): make provider status verification read-only
ericksoa Aug 28, 2026
af6b880
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 28, 2026
ec0537d
fix(shields): preserve native mutable state during status
ericksoa Aug 28, 2026
50b1933
chore(ci): retrigger exact-head validation
ericksoa Aug 28, 2026
3c329bd
chore(shields): clarify read-only lock verification
ericksoa Aug 28, 2026
a0e4660
fix(e2e): reuse images for host Shields changes
ericksoa Aug 28, 2026
71af6fb
fix(shields): preserve proven locked Hermes gateway
ericksoa Aug 28, 2026
847cabc
fix(runtime): rescan reused writer pids
ericksoa Aug 28, 2026
f0cf946
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 28, 2026
97024a2
ci(e2e): pin merged CLI restore action
ericksoa Aug 28, 2026
6da479d
fix(ci): preserve Podman reachability boundaries
ericksoa Aug 29, 2026
270c9b3
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 29, 2026
5531458
fix(ci): preserve readiness mock boundary
ericksoa Aug 29, 2026
c87144d
fix(e2e): socket-activate native Podman service
ericksoa Aug 29, 2026
76030aa
ci(e2e): use socket-activated Podman setup
ericksoa Aug 29, 2026
b8e960d
fix(e2e): reuse images for Podman setup changes
ericksoa Aug 29, 2026
cc610fb
fix(e2e): restore messaging and resume fixtures
ericksoa Aug 29, 2026
8b2f735
fix(e2e): finish messaging and resume fixtures
ericksoa Aug 29, 2026
1b7b8f2
fix(e2e): align messaging and resume runtime evidence
ericksoa Aug 29, 2026
be840b2
fix(messaging): authorize Hermes runtime interpreter
ericksoa Aug 29, 2026
36c4aad
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 29, 2026
72b43ce
fix(e2e): authorize Hermes startup guard credentials
ericksoa Aug 29, 2026
c8cbaff
fix(rebuild): release agent forwards before recreate
ericksoa Aug 29, 2026
bb5bc3c
test(e2e): report Hermes credential alias state
ericksoa Aug 29, 2026
6362079
ci(e2e): reuse images after host rebuild changes
ericksoa Aug 29, 2026
174c9c9
test(e2e): report Hermes process identities
ericksoa Aug 29, 2026
1635dfd
fix(messaging): reconcile Hermes runtime aliases
ericksoa Aug 29, 2026
376853a
fix(messaging): remove channel config before plan discard
ericksoa Aug 29, 2026
fcf4632
test(e2e): accept inert Hermes platform baseline
ericksoa Aug 30, 2026
af84032
fix(rebuild): settle forwards after sandbox deletion
ericksoa Aug 30, 2026
d9f5ae8
ci(e2e): reuse images after tunnel test changes
ericksoa Aug 30, 2026
1f80305
fix(rebuild): isolate forward settlement from stop API
ericksoa Aug 30, 2026
356959f
ci(e2e): reuse images after policy test changes
ericksoa Aug 30, 2026
11047e5
test(e2e): skip workload receipt for onboard help
ericksoa Aug 30, 2026
e23afc1
fix(hermes): preserve supervisor for mutation retry
ericksoa Aug 30, 2026
ae1ed19
test(hermes): preserve ordinary supervisor failure
ericksoa Aug 30, 2026
d6335cf
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 30, 2026
34d3862
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 30, 2026
9df4dbb
fix(rebuild): accept controlled policy receipt rotation
ericksoa Aug 30, 2026
454e592
fix(e2e): reuse images for DCode rebuild changes
ericksoa Aug 30, 2026
5c4bd40
fix(e2e): prepare protected Hermes state volume
ericksoa Aug 30, 2026
6909d5e
fix(e2e): reuse images for host onboarding changes
ericksoa Aug 30, 2026
dac63dc
docs: document native Podman activation
ericksoa Aug 30, 2026
8e4061a
docs: publish native Podman platform status
ericksoa Aug 30, 2026
21729f0
merge: integrate main policy authority changes
ericksoa Aug 30, 2026
97a663b
test: align cli artifact boundary with sealed catalog
ericksoa Aug 30, 2026
222f101
fix(e2e): respect runtime and rebuild authorities
ericksoa Aug 31, 2026
68f041c
test(e2e): register scope upgrade phase helper
ericksoa Aug 31, 2026
a512f5e
fix(policy): preserve channel authority across rebuild
ericksoa Aug 31, 2026
7bb19ec
fix(policy): retire disabled Teams binding on rebuild
ericksoa Aug 31, 2026
c08e21f
fix(policy): restore active Teams binding on rebuild
ericksoa Aug 31, 2026
de7ffa6
chore(ci): retrigger dropped PR workflows
ericksoa Aug 31, 2026
3b06b29
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 31, 2026
63efc1a
test(policy): cover messaging rebuild lifecycle
ericksoa Aug 31, 2026
4b19a18
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 31, 2026
255796a
merge: resolve conflicts with main
github-actions[bot] Aug 31, 2026
2980e5b
merge: resolve conflicts with main
github-actions[bot] Aug 31, 2026
505a93d
fix(runtime): prepare stopped state cleanup resources
ericksoa Aug 31, 2026
75cef14
Merge remote-tracking branch 'origin/feat/b4-h-podman-activation-9145…
ericksoa Aug 31, 2026
d30fe87
fix: preserve OpenClaw state for stopped cleanup
ericksoa Aug 31, 2026
ce99e87
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Aug 31, 2026
edd1247
fix: preserve managed workspace mode typing
ericksoa Aug 31, 2026
cd6a34c
fix(e2e): restore exact candidate image qualification
ericksoa Aug 31, 2026
ba3d431
merge: resolve conflicts with main
github-actions[bot] Sep 1, 2026
322a08b
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Sep 1, 2026
83ac42f
Merge remote-tracking branch 'origin/feat/b4-h-podman-activation-9145…
ericksoa Sep 1, 2026
fb24d13
merge: resolve conflicts with main
github-actions[bot] Sep 1, 2026
2bafc46
fix(podman): verify sandbox after provider activation
ericksoa Sep 1, 2026
ff5e106
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Sep 1, 2026
bc6650f
fix(e2e): restore messaging and snapshot reachability
ericksoa Sep 1, 2026
1775990
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Sep 1, 2026
a132b9d
ci(e2e): pin merged CLI artifact restore
ericksoa Sep 1, 2026
e7fb455
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Sep 1, 2026
363f0d3
merge: resolve conflicts with main
github-actions[bot] Sep 1, 2026
b37246c
fix(podman): accept managed state root modes
ericksoa Sep 1, 2026
7c6aea4
fix(hermes): accept service-owned mutable state
ericksoa Sep 1, 2026
c0316ad
fix(podman): accept cleanup helper image ids
ericksoa Sep 1, 2026
b962cef
Merge remote-tracking branch 'origin/main' into feat/b4-h-podman-acti…
ericksoa Sep 1, 2026
35bd9a9
fix(e2e): isolate PR catalog selector output
ericksoa Sep 1, 2026
ca497e2
fix(e2e): use one managed image catalog authority
ericksoa Sep 1, 2026
585d976
fix(e2e): keep rootless Podman proxy reachable
ericksoa Sep 1, 2026
750426f
fix(e2e): probe rootless Podman proxy locally
ericksoa Sep 2, 2026
719fb24
merge: refresh main for PR CI
ericksoa Sep 2, 2026
7e06c12
fix(ci): remove exact-head CodeQL notices
ericksoa Sep 2, 2026
87e4d54
fix(e2e): normalize rootless Podman topology proofs
ericksoa Sep 2, 2026
dc43567
merge: refresh main after CI fixes
ericksoa Sep 2, 2026
b76dc81
fix(ci): map dashboard runtime provider proof
ericksoa Sep 2, 2026
e00dda4
merge: refresh main advisor registration
ericksoa Sep 2, 2026
ea02928
fix(ci): reconcile current E2E trust boundaries
ericksoa Sep 2, 2026
bee8a81
merge: refresh main Hermes base contract
ericksoa Sep 2, 2026
4639142
fix(ci): refresh merged runtime contract expectations
ericksoa Sep 2, 2026
09d5f83
fix(test): separate lock contention timeout
ericksoa Sep 2, 2026
ca2dd82
fix(security): redact environment-derived diagnostics
ericksoa Sep 2, 2026
0316f31
fix(security): use current CodeQL suppressions
ericksoa Sep 2, 2026
68c9197
merge: refresh main policy diagnostics
ericksoa Sep 2, 2026
e77f540
fix(security): remove remaining CodeQL data flows
ericksoa Sep 2, 2026
9cff774
merge: refresh main Windows inference routing
ericksoa Sep 2, 2026
9945177
fix(ci): assert redacted diagnostic contracts
ericksoa Sep 2, 2026
076d6fa
merge: refresh main advisor pressure controls
ericksoa Sep 2, 2026
ba7eeec
fix(ci): align advisor setup and formatting
ericksoa Sep 2, 2026
07472e2
merge: refresh main runtime tool resolution
ericksoa Sep 2, 2026
ebb851b
merge: refresh main MCP credential handling
ericksoa Sep 2, 2026
bf03efe
merge: refresh main policy and credential contracts
ericksoa Sep 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
306 changes: 306 additions & 0 deletions .github/actions/setup-native-podman-e2e/action.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,306 @@
# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0

name: setup-native-podman-e2e
description: Install the reviewed Podman toolchain artifact and start its rootless API service for E2E.

inputs:
enabled:
description: Prepare Podman when the E2E dispatch selected the native Podman gateway runtime.
required: false
default: "false"

runs:
using: composite
steps:
- id: artifact
name: Resolve native Podman toolchain artifact
if: ${{ inputs.enabled == 'true' }}
shell: bash
env:
RUNNER_ARCH_KIND: ${{ runner.arch }}
run: |
set -euo pipefail
case "$RUNNER_ARCH_KIND" in
X64) architecture=amd64 ;;
ARM64) architecture=arm64 ;;
*)
echo "::error::Native Podman E2E requires a Linux amd64 or arm64 runner" >&2
exit 1
;;
esac
printf 'architecture=%s\n' "$architecture" >>"$GITHUB_OUTPUT"
printf 'name=native-podman-e2e-toolchain-%s\n' "$architecture" >>"$GITHUB_OUTPUT"

- name: Download native Podman toolchain
if: ${{ inputs.enabled == 'true' }}
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ${{ steps.artifact.outputs.name }}
path: ${{ runner.temp }}/native-podman-e2e-toolchain

- name: Start native Podman runtime
if: ${{ inputs.enabled == 'true' }}
shell: bash
env:
EXPECTED_ARCHITECTURE: ${{ steps.artifact.outputs.architecture }}
TOOLCHAIN_DIRECTORY: ${{ runner.temp }}/native-podman-e2e-toolchain
run: |
set -euo pipefail
[[ "$RUNNER_OS" == "Linux" ]]
[[ -d "$TOOLCHAIN_DIRECTORY" && ! -L "$TOOLCHAIN_DIRECTORY" ]]
[[ -z "$(find -P "$TOOLCHAIN_DIRECTORY" -type l -print -quit)" ]]
mapfile -t actual_files < <(
cd "$TOOLCHAIN_DIRECTORY"
find . -type f -print | LC_ALL=C sort
)
expected_files=(
./SHA256SUMS
./bin/pasta
./bin/podman
./libexec/podman/aardvark-dns
./libexec/podman/netavark
./libexec/podman/rootlessport
./manifest.json
./share/containers/containers.conf
)
[[ "${actual_files[*]}" == "${expected_files[*]}" ]]
(
cd "$TOOLCHAIN_DIRECTORY"
sha256sum --check --strict SHA256SUMS
)
jq -e --arg architecture "$EXPECTED_ARCHITECTURE" '
.schemaVersion == 1 and
.kind == "nemoclaw-native-podman-toolchain-v1" and
.architecture == $architecture and
.podmanVersion == "6.1.0" and
.podmanSourceSha == "cade97a52ebdf9dbf9e81de8009015776837a074" and
.netavarkVersion == "2.1.0" and
.netavarkSourceSha == "8e91ad1d947ed325327b638f0cb906bea1f7d0ab" and
.aardvarkDnsVersion == "2.1.0" and
.aardvarkDnsSourceSha == "cd7417681229219059939bdd9f0b3bd9ac9abb08" and
.pastaVersion == "2026_07_28.f8df3f1" and
.pastaSourceArchiveSha256 == "54fc6a3b39b0fcb13182078662886a629032852e186e47a371fd9d7fd20d3958" and
.pastaSourceSha == "f8df3f1b228fe19a74a269334fdfe6cc7d0605ce" and
.goVersion == "1.25.9" and
.rustVersion == "1.88.0"
' "$TOOLCHAIN_DIRECTORY/manifest.json" >/dev/null

sudo env DEBIAN_FRONTEND=noninteractive /usr/bin/apt-get update
sudo env DEBIAN_FRONTEND=noninteractive /usr/bin/apt-get install \
--yes --no-install-recommends \
apparmor btrfs-progs conmon fuse-overlayfs \
golang-github-containers-common iptables nftables runc slirp4netns uidmap

toolchain_install_root=/usr/lib/nemoclaw-native-podman-e2e
sudo install -d --owner=root --group=root --mode=0755 \
"$toolchain_install_root" "$toolchain_install_root/bin"
podman_executable="$toolchain_install_root/bin/podman"
sudo install --owner=root --group=root --mode=0755 \
"$TOOLCHAIN_DIRECTORY/bin/podman" "$podman_executable"
sudo install --owner=root --group=root --mode=0755 \
"$TOOLCHAIN_DIRECTORY/bin/pasta" "$toolchain_install_root/bin/pasta"
export PATH="$toolchain_install_root/bin:$PATH"
printf '%s\n' "$toolchain_install_root/bin" >>"$GITHUB_PATH"
for helper in aardvark-dns netavark rootlessport; do
sudo install -D --owner=root --group=root --mode=0755 \
"$TOOLCHAIN_DIRECTORY/libexec/podman/$helper" \
"/usr/local/libexec/podman/$helper"
done
sudo install --owner=root --group=root --mode=0644 \
"$TOOLCHAIN_DIRECTORY/share/containers/containers.conf" \
/usr/share/containers/containers.conf
[[ "$("$podman_executable" --version)" == "podman version 6.1.0" ]]

execution_user="$(id -un)"
ensure_subordinate_range() {
local file="$1"
local option="$2"
local range_start=100000
local range_end
local conflict_end
if awk -F: -v account="$execution_user" '
$1 == account && $2 ~ /^[0-9]+$/ && $3 ~ /^[0-9]+$/ && $3 >= 65536 { found = 1 }
END { exit found ? 0 : 1 }
' "$file"; then
return
fi
while :; do
((range_start <= 4294901760))
range_end=$((range_start + 65535))
conflict_end="$(awk -F: -v start="$range_start" -v end="$range_end" '
$2 ~ /^[0-9]+$/ && $3 ~ /^[0-9]+$/ {
current_end = $2 + $3 - 1
if ($2 <= end && current_end >= start && current_end > maximum) maximum = current_end
}
END { if (maximum != "") print maximum }
' "$file")"
[[ -n "$conflict_end" ]] || break
range_start=$((conflict_end + 1))
done
range_end=$((range_start + 65535))
sudo usermod "$option" "${range_start}-${range_end}" "$execution_user"
}
ensure_subordinate_range /etc/subuid --add-subuids
ensure_subordinate_range /etc/subgid --add-subgids

podman_command=("$podman_executable")
podman_service_exec="$podman_executable system service --time=0"
if [[ -r /sys/module/apparmor/parameters/enabled ]] && grep -q '^Y' /sys/module/apparmor/parameters/enabled; then
profile="$RUNNER_TEMP/nemoclaw-native-podman-e2e.apparmor"
pasta_profile="$RUNNER_TEMP/nemoclaw-native-pasta-e2e.apparmor"
printf '%s\n' \
'abi <abi/4.0>,' \
'include <tunables/global>' \
'' \
'profile nemoclaw-native-podman-e2e /usr/lib/nemoclaw-native-podman-e2e/bin/podman flags=(unconfined, attach_disconnected) {' \
' userns,' \
'}' >"$profile"
sudo apparmor_parser -r "$profile"
command -v aa-exec >/dev/null
aa_exec_path="$(command -v aa-exec)"
podman_command=("$aa_exec_path" -p nemoclaw-native-podman-e2e -- "$podman_executable")
podman_service_exec="$aa_exec_path -p nemoclaw-native-podman-e2e -- $podman_executable system service --time=0"
printf '%s\n' \
'abi <abi/4.0>,' \
'include <tunables/global>' \
'' \
'profile nemoclaw-native-pasta-e2e /usr/lib/nemoclaw-native-podman-e2e/bin/pasta flags=(unconfined) {' \
' userns,' \
'}' >"$pasta_profile"
sudo apparmor_parser -r "$pasta_profile"
fi

uid="$(id -u)"
gid="$(id -g)"
runtime_directory="/run/user/$uid"
socket_path="$runtime_directory/podman/podman.sock"
sudo systemctl start "user-runtime-dir@${uid}.service" "user@${uid}.service"
systemctl is-active --quiet "user-runtime-dir@${uid}.service"
systemctl is-active --quiet "user@${uid}.service"
[[ -d "$runtime_directory" && ! -L "$runtime_directory" ]]
[[ "$(stat -c '%u:%g:%a' "$runtime_directory")" == "${uid}:${gid}:700" ]]
XDG_RUNTIME_DIR="$runtime_directory" /usr/bin/systemctl --user start dbus.socket
XDG_RUNTIME_DIR="$runtime_directory" /usr/bin/systemctl --user is-active --quiet dbus.socket
[[ -S "$runtime_directory/bus" && ! -L "$runtime_directory/bus" ]]
[[ "$(stat -c '%u' "$runtime_directory/bus")" == "$uid" ]]
install -d -m 0700 "$runtime_directory/podman"
storage_directory="$RUNNER_TEMP/native-podman-e2e-storage"
storage_config="$RUNNER_TEMP/native-podman-e2e-storage.conf"
install -d -m 0700 "$storage_directory/runroot" "$storage_directory/graphroot"
printf '%s\n' \
'[storage]' \
'driver = "overlay"' \
"runroot = \"$storage_directory/runroot\"" \
"graphroot = \"$storage_directory/graphroot\"" >"$storage_config"
containers_config="$RUNNER_TEMP/native-podman-e2e-containers.conf"
printf '%s\n' \
'[containers]' \
'log_driver = "k8s-file"' \
'' \
'[engine]' \
'runtime = "runc"' \
'' \
'[network]' \
'firewall_driver = "nftables"' >"$containers_config"
export CONTAINERS_CONF="$containers_config"
export CONTAINERS_STORAGE_CONF="$storage_config"
export DBUS_SESSION_BUS_ADDRESS="unix:path=$runtime_directory/bus"
export XDG_RUNTIME_DIR="$runtime_directory"
service_name=nemoclaw-native-podman-e2e
service_environment="$RUNNER_TEMP/native-podman-e2e-service.env"
service_unit_directory="$HOME/.config/systemd/user"
service_unit="$service_unit_directory/$service_name.service"
socket_unit="$service_unit_directory/$service_name.socket"
install -d -m 0700 "$service_unit_directory"
printf '%s\n' \
"CONTAINERS_CONF=$containers_config" \
"CONTAINERS_STORAGE_CONF=$storage_config" \
"DBUS_SESSION_BUS_ADDRESS=unix:path=$runtime_directory/bus" \
"PATH=$toolchain_install_root/bin:$PATH" \
"XDG_RUNTIME_DIR=$runtime_directory" >"$service_environment"
chmod 0600 "$service_environment"
printf '%s\n' \
'[Unit]' \
'Description=NemoClaw native Podman E2E API service' \
"Requires=$service_name.socket" \
"After=$service_name.socket dbus.socket" \
'' \
'[Service]' \
'Type=exec' \
'Delegate=true' \
'KillMode=process' \
'Environment=PODMAN_SYSTEMD_UNIT=%n' \
"EnvironmentFile=$service_environment" \
"ExecStart=$podman_service_exec" >"$service_unit"
printf '%s\n' \
'[Unit]' \
'Description=NemoClaw native Podman E2E API socket' \
'' \
'[Socket]' \
"ListenStream=$socket_path" \
'SocketMode=0600' \
'DirectoryMode=0700' \
'RemoveOnStop=true' \
"Service=$service_name.service" >"$socket_unit"
chmod 0600 "$service_unit" "$socket_unit"
/usr/bin/systemctl --user daemon-reload
/usr/bin/systemctl --user start "$service_name.socket"
/usr/bin/systemctl --user is-active --quiet "$service_name.socket"
service_ready=false
for attempt in $(seq 1 30); do
if "${podman_command[@]}" --url "unix://$socket_path" info --format json \
>"$RUNNER_TEMP/native-podman-e2e-info.json" 2>/dev/null; then
service_ready=true
break
fi
if [[ "$attempt" -lt 30 ]]; then
sleep 1
fi
done
if [[ "$service_ready" != true ]]; then
echo "::error::Native Podman API service did not become ready" >&2
/usr/bin/systemctl --user status "$service_name.socket" "$service_name.service" \
--no-pager --full >&2 || true
/usr/bin/journalctl --user --unit "$service_name.service" --no-pager --lines=100 >&2 || true
sudo dmesg | grep -E 'apparmor=.*DENIED' | tail -n 20 >&2 || true
exit 1
fi
[[ -S "$socket_path" ]]
/usr/bin/systemctl --user is-active --quiet "$service_name.service"
service_pid="$(/usr/bin/systemctl --user show "$service_name.service" --property=MainPID --value)"
[[ "$service_pid" =~ ^[1-9][0-9]*$ ]]
[[ "$(curl --fail --silent --show-error --noproxy '*' --unix-socket "$socket_path" http://localhost/_ping)" == "OK" ]]
jq -e '
(.host.security.rootless // .Host.Security.Rootless) == true and
((.host.cgroupVersion // .Host.CgroupVersion) | ascii_downcase) == "v2" and
((.host.ociRuntime.name // .Host.OCIRuntime.Name) | ascii_downcase) == "runc"
' "$RUNNER_TEMP/native-podman-e2e-info.json" >/dev/null

# A Podman matrix row is qualification evidence only when Docker cannot
# satisfy an accidental legacy probe or resource operation. Keep this
# enforcement at the reusable runtime-setup boundary, never in an E2E
# scenario, so every Podman row proves the same provider isolation.
sudo systemctl stop docker.service docker.socket 2>/dev/null || true
sudo systemctl mask --runtime docker.service docker.socket 2>/dev/null || true
sudo pkill -TERM -x dockerd 2>/dev/null || true
sudo rm -f /var/run/docker.sock /run/docker.sock
! systemctl is-active --quiet docker.service
! systemctl is-active --quiet docker.socket
! pgrep -x dockerd >/dev/null
[[ ! -S /var/run/docker.sock && ! -S /run/docker.sock ]]
if command -v docker >/dev/null 2>&1 && docker info >/dev/null 2>&1; then
echo "::error::Podman E2E isolation failed because Docker remains reachable" >&2
exit 1
fi

sudo ip address replace 169.254.2.2/32 dev lo
{
printf 'CONTAINERS_CONF=%s\n' "$containers_config"
printf 'CONTAINERS_STORAGE_CONF=%s\n' "$storage_config"
printf 'DBUS_SESSION_BUS_ADDRESS=unix:path=%s/bus\n' "$runtime_directory"
printf 'NEMOCLAW_NATIVE_PODMAN_SERVICE_PID=%s\n' "$service_pid"
printf 'OPENSHELL_PODMAN_SOCKET=%s\n' "$socket_path"
printf 'PATH=%s:%s\n' "$toolchain_install_root/bin" "$PATH"
printf 'XDG_RUNTIME_DIR=%s\n' "$runtime_directory"
} >>"$GITHUB_ENV"
88 changes: 88 additions & 0 deletions .github/actions/stage-native-podman-e2e-toolchains/action.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,88 @@
# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0

name: stage-native-podman-e2e-toolchains
description: Copy the reviewed native Podman toolchains into the current E2E run.

inputs:
enabled:
description: Stage the toolchains when native Podman E2E is selected.
required: false
default: "false"
github-token:
description: Read-only token for retrieving the immutable source-run artifacts.
required: true

runs:
using: composite
steps:
- name: Verify immutable native Podman E2E toolchains
if: ${{ inputs.enabled == 'true' }}
shell: bash
env:
GH_TOKEN: ${{ inputs.github-token }}
SOURCE_RUN_ID: "32523050217"
run: |
set -euo pipefail
verify_artifact() {
local artifact_id="$1"
local artifact_name="$2"
local artifact_digest="$3"
gh api "repos/NVIDIA/NemoClaw/actions/artifacts/$artifact_id" \
--jq '[.id,.name,.expired,.digest,.workflow_run.id] | @tsv' \
| awk -F '\t' \
-v expected_id="$artifact_id" \
-v expected_name="$artifact_name" \
-v expected_digest="$artifact_digest" \
-v expected_run="$SOURCE_RUN_ID" \
'$1 == expected_id && $2 == expected_name && $3 == "false" && $4 == expected_digest && $5 == expected_run { found = 1 }
END { exit found ? 0 : 1 }'
}
verify_artifact \
9461520882 \
native-runtime-podman-toolchain-amd64 \
sha256:e8f54bf0f2419c4f852d4a240b78176031758ebd24206859a370c6acce8e8b8e
verify_artifact \
9461493915 \
native-runtime-podman-toolchain-arm64 \
sha256:e0bd6f308a18fe7daf7f15b2c72dd852d12afd13bd70afdcf6555c91e3617da9

- name: Download immutable native Podman amd64 toolchain
if: ${{ inputs.enabled == 'true' }}
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
github-token: ${{ inputs.github-token }}
repository: NVIDIA/NemoClaw
run-id: "32523050217"
name: native-runtime-podman-toolchain-amd64
path: ${{ runner.temp }}/native-podman-e2e-toolchain-amd64

- name: Download immutable native Podman arm64 toolchain
if: ${{ inputs.enabled == 'true' }}
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
github-token: ${{ inputs.github-token }}
repository: NVIDIA/NemoClaw
run-id: "32523050217"
name: native-runtime-podman-toolchain-arm64
path: ${{ runner.temp }}/native-podman-e2e-toolchain-arm64

- name: Publish native Podman amd64 toolchain for this run
if: ${{ inputs.enabled == 'true' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: native-podman-e2e-toolchain-amd64
path: ${{ runner.temp }}/native-podman-e2e-toolchain-amd64/
if-no-files-found: error
retention-days: 3
compression-level: 0

- name: Publish native Podman arm64 toolchain for this run
if: ${{ inputs.enabled == 'true' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: native-podman-e2e-toolchain-arm64
path: ${{ runner.temp }}/native-podman-e2e-toolchain-arm64/
if-no-files-found: error
retention-days: 3
compression-level: 0
Loading
Loading