Skip to content
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
Show all changes
76 commits
Select commit Hold shift + click to select a range
e2afccd
test(e2e): execute native runtime qualification
ericksoa Aug 16, 2026
c3327ac
fix(e2e): authorize admin candidate qualification
ericksoa Aug 16, 2026
5db3818
fix(e2e): harden qualification evidence
ericksoa Aug 16, 2026
26f4110
fix(e2e): preserve receipt read boundary
ericksoa Aug 16, 2026
c3d65f9
refactor(e2e): linearize native qualification test
ericksoa Aug 16, 2026
4e835cb
test(e2e): cover arm64 qualification receipts
ericksoa Aug 16, 2026
d0bfd86
fix(e2e): confirm Podman service cleanup
ericksoa Aug 16, 2026
2efe4e8
fix(e2e): prepare native qualification runners
ericksoa Aug 16, 2026
b788822
fix(e2e): pin native Podman qualification
ericksoa Aug 16, 2026
20cdd80
fix(e2e): build pinned Podman 6 qualification toolchain
ericksoa Aug 16, 2026
695c656
fix(e2e): use allowed Rust toolchain action
ericksoa Aug 16, 2026
54a65fc
fix(e2e): keep Podman toolchain ABI portable
ericksoa Aug 16, 2026
566ed84
fix(e2e): use portable Podman OpenPGP backend
ericksoa Aug 16, 2026
9e33b53
fix(e2e): validate protected installer receipt metadata
ericksoa Aug 16, 2026
7e89c81
fix(e2e): execute qualification from candidate root
ericksoa Aug 16, 2026
dcda59e
fix(e2e): distinguish PR source branch identity
ericksoa Aug 16, 2026
00e5a16
fix(e2e): provision rootless subordinate IDs
ericksoa Aug 16, 2026
724d7b8
fix(e2e): bind rootless qualification storage
ericksoa Aug 16, 2026
e40e2f0
fix(e2e): harden rootless qualification host lifecycle
ericksoa Aug 16, 2026
73a2c2c
test(e2e): keep lifecycle fixtures linear
ericksoa Aug 16, 2026
ac68c6e
fix(e2e): preserve qualification user runtime directory
ericksoa Aug 16, 2026
921efe4
fix(e2e): bind qualified Podman executable authority
ericksoa Aug 16, 2026
8548a37
fix(e2e): isolate qualified Podman executable
ericksoa Aug 16, 2026
da1e619
fix(e2e): use stable qualified executable parent
ericksoa Aug 16, 2026
cb7b609
fix(e2e): bind native Podman network authority
ericksoa Aug 16, 2026
9711d7e
fix(runtime): bind Podman mapping preflight to endpoint
ericksoa Aug 16, 2026
bddd60f
fix(e2e): require native rootless overlay
ericksoa Aug 16, 2026
02132c2
fix(e2e): harden native qualification resources
ericksoa Aug 16, 2026
94c1162
fix(e2e): isolate qualification network and auth
ericksoa Aug 16, 2026
afbeaf5
fix(e2e): stabilize native qualification identity
ericksoa Aug 16, 2026
94efdf0
fix(e2e): prove failed network cleanup
ericksoa Aug 16, 2026
5ef5ee7
test(e2e): keep network fixture branchless
ericksoa Aug 16, 2026
6c51038
fix(e2e): activate qualification user bus
ericksoa Aug 16, 2026
db20d5f
fix(e2e): accept systemd bus group ownership
ericksoa Aug 16, 2026
a20254e
fix(e2e): verify user bus access
ericksoa Aug 16, 2026
e0d9f2f
fix(e2e): secure registry auth inspection
ericksoa Aug 16, 2026
e91044e
fix(e2e): harden qualification isolation
ericksoa Aug 16, 2026
deb483b
fix(e2e): route inference within provider network
ericksoa Aug 16, 2026
be19dc7
fix(e2e): complete native inference setup
ericksoa Aug 16, 2026
5031ceb
fix(e2e): harden native qualification execution
ericksoa Aug 16, 2026
65d16ce
fix(e2e): validate pasta version line
ericksoa Aug 16, 2026
c1e73a9
fix(e2e): use valid lifecycle sandbox names
ericksoa Aug 16, 2026
0e9d559
fix(e2e): accept safe physical GPU identities
ericksoa Aug 16, 2026
eca6e68
test(e2e): report rejected GPU identity rows
ericksoa Aug 16, 2026
6ef48ce
fix(e2e): override GPU probe entrypoint
ericksoa Aug 16, 2026
22cee86
test(e2e): report inference exit diagnostics
ericksoa Aug 16, 2026
f0bac8d
fix(e2e): launch vllm serve explicitly
ericksoa Aug 16, 2026
25acda5
fix(e2e): harden failed-case cleanup
ericksoa Aug 16, 2026
a56b5c7
test(e2e): keep cleanup fixtures linear
ericksoa Aug 16, 2026
1b3ba2b
fix(e2e): preserve cleanup engine ownership
ericksoa Aug 16, 2026
240240c
fix(e2e): close qualification review gaps
ericksoa Aug 16, 2026
b60bb48
test(e2e): keep lifecycle fixture branchless
ericksoa Aug 16, 2026
d00ffec
test(e2e): enforce lifecycle fixture rewrites
ericksoa Aug 16, 2026
948941d
chore: merge main into B4-G qualification
ericksoa Aug 16, 2026
f78d002
fix(uninstall): retire portable config directories
ericksoa Aug 16, 2026
3f5ee67
Merge remote-tracking branch 'origin/main' into feat/b4-g-native-qual…
ericksoa Aug 16, 2026
8a70431
test(uninstall): satisfy conditional guardrail
ericksoa Aug 16, 2026
ce95d85
test(uninstall): align live directory retirement proof
ericksoa Aug 16, 2026
ce6248e
test(security): exercise YAML config boundary
ericksoa Aug 16, 2026
2dbe18b
fix(uninstall): preserve large config directories
ericksoa Aug 16, 2026
977c6e0
Merge branch 'main' into feat/b4-g-native-qualification-9144
cv Aug 16, 2026
f16d407
docs(uninstall): document empty directory cleanup
cv Aug 16, 2026
5b79e5a
docs(e2e): prepare exact workflow checkout
cv Aug 16, 2026
6804f09
docs(e2e): clarify source-branch credential boundary
cv Aug 16, 2026
562528a
docs(e2e): distinguish candidate credential access
cv Aug 17, 2026
2cd71fa
test(e2e): satisfy growth guardrails
ericksoa Aug 16, 2026
f256d07
test(e2e): clarify candidate workflow authority
ericksoa Aug 17, 2026
504fcf7
test(security): preserve credential coverage ratchet
ericksoa Aug 17, 2026
c534676
fix(e2e): require trusted-main native qualification
ericksoa Aug 17, 2026
8834744
fix(e2e): reject candidate qualification rows
ericksoa Aug 17, 2026
1fb09c4
docs(e2e): clarify manual dispatch inputs
ericksoa Aug 17, 2026
588eff1
merge: resolve conflicts with main
github-actions[bot] Aug 17, 2026
d674820
docs(e2e): correct qualification evidence guidance
cv Aug 17, 2026
0ed8b98
docs(e2e): identify qualification inputs
cv Aug 17, 2026
5a13fec
docs(e2e): separate qualification selectors
cv Aug 17, 2026
54a3c3b
docs(e2e): name credential-bearing preparation
cv Aug 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
219 changes: 191 additions & 28 deletions .github/workflows/e2e.yaml

Large diffs are not rendered by default.

86 changes: 62 additions & 24 deletions scripts/checks/run-native-runtime-installer-qualification.sh
Original file line number Diff line number Diff line change
Expand Up @@ -98,6 +98,7 @@ verify_checkout() {
*) fail "$label has an unexpected origin repository." ;;
esac
assert_checkout_has_no_git_credentials "$checkout" "$label"
printf '%s\n' "$revision"
}

verify_committed_file() {
Expand Down Expand Up @@ -191,14 +192,51 @@ assert_docker_unavailable() {
[[ ! -S "$socket_path" ]] \
|| fail "A Docker socket exists during the ${phase} check."
done < <(docker_socket_paths)

printf '%s\n' \
'{"dockerCommandGuarded":true,"dockerEnvironmentVariablesUnset":true,"dockerServiceInactive":true,"dockerSocketUnitInactive":true,"dockerdProcessNameAbsent":true,"defaultSocketPathsAbsent":true}'
}

run_native_runtime_installer_qualification() {
candidate_checkout=""
candidate_sha=""
expected_installer_sha256=""
expected_architecture=""
artifact_dir_input=""
local candidate_checkout=""
local candidate_sha=""
local expected_installer_sha256=""
local expected_architecture=""
local artifact_dir_input=""
local artifact_parent=""
local artifact_name=""
local artifact_dir=""
local runner_architecture=""
local candidate_installer=""
local candidate_setup_script=""
local qualification_root=""
local qualification_home=""
local qualification_tmp=""
local docker_guard_dir=""
local managed_payload_root=""
local verified_script_dir=""
local verified_installer=""
local verified_setup_script=""
local installed_checkout=""
local receipt_stage=""
local docker_guard=""
local docker_guard_sha256=""
local candidate_status=0
local verified_candidate_revision=""
local installed_revision=""
local pre_execution_docker_posture=""
local post_execution_docker_posture=""

cleanup() {
if [[ -n "$receipt_stage" && -d "$receipt_stage" && ! -L "$receipt_stage" ]]; then
rm -rf -- "$receipt_stage"
fi
if [[ -n "$qualification_root" && -d "$qualification_root" && ! -L "$qualification_root" ]]; then
rm -rf -- "$qualification_root"
fi
}
trap cleanup EXIT

while [[ "$#" -gt 0 ]]; do
case "$1" in
--candidate-checkout)
Expand Down Expand Up @@ -272,7 +310,9 @@ run_native_runtime_installer_qualification() {

candidate_installer="${candidate_checkout}/scripts/install.sh"
candidate_setup_script="${candidate_checkout}/scripts/setup-jetson.sh"
verify_checkout "$candidate_checkout" "$candidate_sha" "The candidate checkout"
verified_candidate_revision="$(
verify_checkout "$candidate_checkout" "$candidate_sha" "The candidate checkout"
)"
verify_installer \
"$candidate_checkout" \
"$candidate_sha" \
Expand Down Expand Up @@ -303,16 +343,6 @@ run_native_runtime_installer_qualification() {
"$managed_payload_root" \
"$verified_script_dir"

cleanup() {
if [[ -n "${receipt_stage:-}" && -d "$receipt_stage" && ! -L "$receipt_stage" ]]; then
rm -rf -- "$receipt_stage"
fi
if [[ -n "${qualification_root:-}" && -d "$qualification_root" && ! -L "$qualification_root" ]]; then
rm -rf -- "$qualification_root"
fi
}
trap cleanup EXIT

cp -- "$candidate_installer" "$verified_installer"
cp -- "$candidate_setup_script" "$verified_setup_script"
chmod 500 "$verified_installer" "$verified_setup_script"
Expand All @@ -336,9 +366,10 @@ run_native_runtime_installer_qualification() {
PATH="${docker_guard_dir}:${PATH}"
export PATH

assert_docker_unavailable "pre-execution" "$docker_guard" "$docker_guard_sha256"
pre_execution_docker_posture="$(
assert_docker_unavailable "pre-execution" "$docker_guard" "$docker_guard_sha256"
)"

candidate_status=0
# The child shell expands positional parameters inside this literal program.
# shellcheck disable=SC2016
env -i \
Expand Down Expand Up @@ -366,11 +397,15 @@ run_native_runtime_installer_qualification() {
install_nemoclaw_before_onboarding
' _ "$verified_installer" "$verified_script_dir" || candidate_status=$?

assert_docker_unavailable "post-execution" "$docker_guard" "$docker_guard_sha256"
post_execution_docker_posture="$(
assert_docker_unavailable "post-execution" "$docker_guard" "$docker_guard_sha256"
)"
[[ "$candidate_status" -eq 0 ]] \
|| fail "The candidate installer phase executor exited with status ${candidate_status}."

verify_checkout "$installed_checkout" "$candidate_sha" "The installed checkout"
installed_revision="$(
verify_checkout "$installed_checkout" "$candidate_sha" "The installed checkout"
)"
verify_installer \
"$installed_checkout" \
"$candidate_sha" \
Expand All @@ -382,16 +417,16 @@ run_native_runtime_installer_qualification() {
"$expected_installer_sha256" "$candidate_sha" "$runner_architecture" \
>"${receipt_stage}/invocation.json"
printf '{"receiptVersion":1,"repository":"%s","revision":"%s","installerSha256":"%s"}\n' \
"$CANONICAL_REPOSITORY" "$candidate_sha" "$expected_installer_sha256" \
"$CANONICAL_REPOSITORY" "$verified_candidate_revision" "$expected_installer_sha256" \
>"${receipt_stage}/candidate-source.json"
printf '{"receiptVersion":1,"repository":"%s","requestedRevision":"%s","installedRevision":"%s","installMode":"managed","installerSha256":"%s"}\n' \
"$CANONICAL_REPOSITORY" "$candidate_sha" "$candidate_sha" "$expected_installer_sha256" \
"$CANONICAL_REPOSITORY" "$candidate_sha" "$installed_revision" "$expected_installer_sha256" \
>"${receipt_stage}/installed-source.json"
printf '{"receiptVersion":1,"requested":"%s","runner":"%s"}\n' \
"$expected_architecture" "$runner_architecture" \
>"${receipt_stage}/architecture.json"
printf '%s\n' \
'{"receiptVersion":1,"preExecution":{"dockerCommandGuarded":true,"dockerEnvironmentVariablesUnset":true,"dockerServiceInactive":true,"dockerSocketUnitInactive":true,"dockerdProcessNameAbsent":true,"defaultSocketPathsAbsent":true},"postExecution":{"dockerCommandGuarded":true,"dockerEnvironmentVariablesUnset":true,"dockerServiceInactive":true,"dockerSocketUnitInactive":true,"dockerdProcessNameAbsent":true,"defaultSocketPathsAbsent":true}}' \
printf '{"receiptVersion":1,"preExecution":%s,"postExecution":%s}\n' \
"$pre_execution_docker_posture" "$post_execution_docker_posture" \
>"${receipt_stage}/docker-absence.json"

bounded_file "${receipt_stage}/installer.sh" "$MAX_INSTALLER_BYTES"
Expand All @@ -409,6 +444,9 @@ run_native_runtime_installer_qualification() {
receipt_stage=""

printf 'Native runtime installer qualification receipts: %s\n' "$artifact_dir"
cleanup
trap - EXIT
unset -f cleanup
}

if [[ "${BASH_SOURCE[0]:-}" == "$0" ]]; then
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
export const NATIVE_RUNTIME_QUALIFICATION_PROTECTED_REPOSITORY = "NVIDIA/NemoClaw";
/** The trusted collector is separate and rejects evidence emitted by its own workflow. */
export const NATIVE_RUNTIME_QUALIFICATION_PRODUCER_WORKFLOW =
".github/workflows/native-runtime-qualification.yaml";
".github/workflows/e2e.yaml";

export interface NativeRuntimeQualificationProtectedRun {
readonly repository: string;
Expand Down
Loading
Loading