Skip to content
Draft
Show file tree
Hide file tree
Changes from 52 commits
Commits
Show all changes
65 commits
Select commit Hold shift + click to select a range
e3c58b5
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 8, 2026
689fe25
Merge branch 'main' into patch-walker/langchain-deep-agents-code-0.1.…
prekshivyas Aug 10, 2026
69de1f1
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 10, 2026
9c3eaf4
Merge branch 'main' into patch-walker/langchain-deep-agents-code-0.1.…
prekshivyas Aug 11, 2026
3a406ef
Merge branch 'main' into patch-walker/langchain-deep-agents-code-0.1.…
prekshivyas Aug 11, 2026
ce0bf4d
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 11, 2026
82b5b01
Merge branch 'main' into patch-walker/langchain-deep-agents-code-0.1.…
prekshivyas Aug 11, 2026
130ed97
Merge branch 'main' into patch-walker/langchain-deep-agents-code-0.1.…
prekshivyas Aug 11, 2026
4fca1ab
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 11, 2026
5a2ce61
Merge branch 'main' into patch-walker/langchain-deep-agents-code-0.1.…
prekshivyas Aug 11, 2026
3dec810
merge: sync main into nemopatch draft
prekshivyas Aug 11, 2026
d63a0e9
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 11, 2026
a08d5a5
merge: sync main into nemopatch draft
prekshivyas Aug 11, 2026
57434bb
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 11, 2026
088790f
merge: sync main into nemopatch draft
prekshivyas Aug 11, 2026
2619fb5
Merge branch 'main' into patch-walker/langchain-deep-agents-code-0.1.…
prekshivyas Aug 11, 2026
aa76fcb
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 11, 2026
59291cc
merge: sync main into nemopatch draft
prekshivyas Aug 11, 2026
296b3cc
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 11, 2026
9a2a2d4
merge: sync main into nemopatch draft
prekshivyas Aug 11, 2026
6784adb
merge: sync main into nemopatch draft
prekshivyas Aug 11, 2026
956be2d
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 11, 2026
15c0018
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 11, 2026
ed74486
merge: sync main into nemopatch draft
prekshivyas Aug 11, 2026
e230314
chore(deps): update langchain deep agents code to 0.1.54
prekshivyas Aug 11, 2026
55ba58c
fix(deps): repair Deep Agents 0.1.54 contracts
prekshivyas Aug 11, 2026
de82eec
test(deps): satisfy conditional guardrail
prekshivyas Aug 11, 2026
42f12a9
fix(deps): preserve Deep Agents server session launch
prekshivyas Aug 11, 2026
6fd6d2d
fix(deps): match Deep Agents locked server lifecycle
prekshivyas Aug 11, 2026
5cc4437
fix(deps): align Deep Agents profile source trust
prekshivyas Aug 11, 2026
0508e59
fix(deps): use custom backend without fake provider
prekshivyas Aug 11, 2026
f143985
test(deps): name validation backend regression
prekshivyas Aug 11, 2026
6b8f259
Merge branch 'main' into patch-walker/langchain-deep-agents-code-0.1.…
prekshivyas Aug 12, 2026
841c9b8
fix(deps): preserve Deep Agents MCP search catalog
prekshivyas Aug 12, 2026
6c953ac
test(deps): classify Deep Agents MCP fixture as read-only
prekshivyas Aug 12, 2026
687c1c3
fix(deps): preserve local subagent tool catalogs
prekshivyas Aug 12, 2026
92dcd03
fix(onboard): scope recreation probe to gateway
prekshivyas Aug 12, 2026
4b26e86
docs(deepagents): update managed runtime versions
prekshivyas Aug 12, 2026
3f2f349
refactor(onboard): keep gateway injection net neutral
prekshivyas Aug 12, 2026
24501a8
fix(onboard): scope DCode identity to gateway
prekshivyas Aug 12, 2026
f0df23a
fix(onboard): honor explicit sandbox recreation
prekshivyas Aug 12, 2026
7d516c7
test(e2e): use supported DCode switch model
prekshivyas Aug 12, 2026
42c04eb
test(e2e): discover authorized DCode switch model
prekshivyas Aug 12, 2026
bc62070
test(e2e): clarify model preference order
prekshivyas Aug 12, 2026
9f74564
test(e2e): load inference probe with tsx
prekshivyas Aug 12, 2026
ea8856e
merge: sync Deep Agents upgrade with main
prekshivyas Aug 12, 2026
d8f1c09
fix(e2e): type authorized model selector
prekshivyas Aug 12, 2026
7cde14e
test(onboard): update gateway-scoped fixtures
prekshivyas Aug 12, 2026
87fccea
fix(deepagents): preserve thread auto-approval
prekshivyas Aug 12, 2026
9a0abe5
test(deepagents): model approval mode in disclosure fixture
prekshivyas Aug 12, 2026
f5d2a06
test(deepagents): accept stable marker text
prekshivyas Aug 12, 2026
a800a7f
merge: sync Deep Agents upgrade with main
prekshivyas Aug 12, 2026
d24a04f
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 14, 2026
682b192
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 14, 2026
a73ca49
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 14, 2026
8852ab3
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 14, 2026
9d6c398
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 14, 2026
98a1c85
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 14, 2026
e88b9c2
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 14, 2026
b7833ad
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 14, 2026
dd7b711
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 14, 2026
9616765
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 14, 2026
f473c25
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 15, 2026
cad0db2
chore(deps): update langchain deep agents code to 0.1.55
prekshivyas Aug 15, 2026
789b74f
ci(images): overlay candidate staging dependencies
prekshivyas Aug 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
149 changes: 138 additions & 11 deletions .github/workflows/managed-images.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -103,6 +103,29 @@ jobs:
printf 'NemoClaw source commit: %s\n' "$STAGING_QA_SOURCE_SHA"
} >> "$GITHUB_STEP_SUMMARY"

# NemoPatch exact Deep Agents candidate-base boundary.
# Preserve the recorded staging tree and replace only the dependency inputs
# that the candidate base image owns.
- name: Overlay exact PR dependency inputs on staging QA base
shell: bash
run: |
set -euo pipefail
candidate_root="$GITHUB_WORKSPACE/candidate"
staging_root="$GITHUB_WORKSPACE/staging-qa-base-source"
for relative in \
agents/langchain-deepagents-code/Dockerfile.base \
agents/langchain-deepagents-code/requirements.lock
do
source_file="$candidate_root/$relative"
destination_file="$staging_root/$relative"
if [ ! -f "$source_file" ] || [ -L "$source_file" ] || [ ! -f "$destination_file" ] || [ -L "$destination_file" ]; then
echo "ERROR: staging QA dependency input is missing, unsafe, or changed shape: $relative" >&2
exit 1
fi
install -m 0644 "$source_file" "$destination_file"
done
printf '\nCandidate dependency inputs: %s\n' "$CANDIDATE_SHA" >> "$GITHUB_STEP_SUMMARY"

- name: Reproduce staging discovery permission drift
shell: bash
working-directory: candidate
Expand Down Expand Up @@ -335,7 +358,89 @@ jobs:
with:
node-version: 22.19.0

- name: Validate exact Deep Agents PR base build args
if: matrix.agent == 'langchain-deepagents-code'
shell: bash
run: scripts/check-production-build-args.sh -f agents/langchain-deepagents-code/Dockerfile.base

- name: Log in to GHCR for exact same-repository PR digest
if: github.event.pull_request.head.repo.full_name == github.repository
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

- name: Publish exact Deep Agents PR base by digest
id: candidate-base-build
if: matrix.agent == 'langchain-deepagents-code' && github.event.pull_request.head.repo.full_name == github.repository
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
file: agents/langchain-deepagents-code/Dockerfile.base
platforms: linux/amd64
outputs: type=image,name=${{ matrix.base_repository }},push-by-digest=true,name-canonical=true,push=true
cache-from: type=registry,ref=${{ matrix.base_repository }}:buildcache-linux-amd64
provenance: false
sbom: false

- name: Bind exact Deep Agents PR base
id: candidate-base
if: matrix.agent == 'langchain-deepagents-code' && github.event.pull_request.head.repo.full_name == github.repository
shell: bash
env:
BASE_REPOSITORY: ${{ matrix.base_repository }}
DIGEST: ${{ steps.candidate-base-build.outputs.digest }}
run: |
set -euo pipefail
if [[ ! "$DIGEST" =~ ^sha256:[0-9a-f]{64}$ ]]; then
echo "ERROR: exact Deep Agents PR base build returned an invalid digest." >&2
exit 1
fi
reference="${BASE_REPOSITORY}@${DIGEST}"
raw="$RUNNER_TEMP/deep-agents-pr-base.raw"
docker buildx imagetools inspect "$reference" --raw > "$raw"
actual="sha256:$(sha256sum "$raw" | awk '{print $1}')"
if [ "$actual" != "$DIGEST" ]; then
echo "ERROR: exact Deep Agents PR base bytes do not match the build digest." >&2
exit 1
fi
printf 'ref=%s\n' "$reference" >> "$GITHUB_OUTPUT"
printf '### Deep Agents exact PR base\n\n`%s`\n' "$reference" >> "$GITHUB_STEP_SUMMARY"

- name: Build exact Deep Agents fork PR base locally
id: candidate-base-local-build
if: matrix.agent == 'langchain-deepagents-code' && github.event.pull_request.head.repo.full_name != github.repository
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
file: agents/langchain-deepagents-code/Dockerfile.base
platforms: linux/amd64
load: true
push: false
tags: nemoclaw-pr-base/${{ matrix.agent }}:${{ github.event.pull_request.head.sha }}
cache-from: type=registry,ref=${{ matrix.base_repository }}:buildcache-linux-amd64
provenance: false
sbom: false

- name: Bind exact Deep Agents fork PR base
id: candidate-base-local
if: matrix.agent == 'langchain-deepagents-code' && github.event.pull_request.head.repo.full_name != github.repository
shell: bash
env:
REFERENCE: nemoclaw-pr-base/${{ matrix.agent }}:${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
image_id="$(docker image inspect --format '{{.Id}}' "$REFERENCE")"
if [[ ! "$image_id" =~ ^sha256:[0-9a-f]{64}$ ]]; then
echo "ERROR: exact Deep Agents fork PR base did not resolve to an immutable local image ID." >&2
exit 1
fi
printf 'ref=%s\n' "$REFERENCE" >> "$GITHUB_OUTPUT"
printf '### Deep Agents exact fork PR base\n\n`%s` (`%s`)\n' "$REFERENCE" "$image_id" >> "$GITHUB_STEP_SUMMARY"

- name: Resolve exact linux/amd64 PR base
if: matrix.agent != 'langchain-deepagents-code'
id: base
shell: bash
env:
Expand Down Expand Up @@ -387,7 +492,7 @@ jobs:
- name: Validate PR managed-image build args
shell: bash
env:
BASE_REFERENCE: ${{ steps.base.outputs.ref }}
BASE_REFERENCE: ${{ steps.candidate-base.outputs.ref || steps.candidate-base-local.outputs.ref || steps.base.outputs.ref }}
DOCKERFILE: ${{ matrix.dockerfile }}
run: |
set -euo pipefail
Expand All @@ -398,6 +503,7 @@ jobs:
--build-arg "NEMOCLAW_MANAGED_IMAGE_RUNTIME_USER=root"

- name: Build PR managed image locally
if: matrix.agent != 'langchain-deepagents-code' || github.event.pull_request.head.repo.full_name == github.repository
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
Expand All @@ -416,13 +522,42 @@ jobs:
io.nvidia.nemoclaw.managed-image.capabilities=1
io.nvidia.nemoclaw.managed-image.cohort=ghrun-${{ github.run_id }}-${{ github.run_attempt }}
build-args: |
BASE_IMAGE=${{ steps.base.outputs.ref }}
BASE_IMAGE=${{ steps.candidate-base.outputs.ref || steps.candidate-base-local.outputs.ref || steps.base.outputs.ref }}
NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION=1
NEMOCLAW_MANAGED_IMAGE_RUNTIME_USER=root
cache-from: type=registry,ref=ghcr.io/nvidia/nemoclaw/${{ matrix.agent }}-sandbox:buildcache-linux-amd64
provenance: false
sbom: false

- name: Build fork PR managed image locally from exact Deep Agents base
if: matrix.agent == 'langchain-deepagents-code' && github.event.pull_request.head.repo.full_name != github.repository
shell: bash
env:
AGENT: ${{ matrix.agent }}
BASE_REFERENCE: ${{ steps.candidate-base-local.outputs.ref }}
COHORT: ghrun-${{ github.run_id }}-${{ github.run_attempt }}
DOCKERFILE: ${{ matrix.dockerfile }}
IMAGE_REFERENCE: ${{ matrix.image }}:${{ github.event.pull_request.head.sha }}
REVISION: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
docker buildx build --builder default --load \
--platform linux/amd64 \
--file "$DOCKERFILE" \
--tag "$IMAGE_REFERENCE" \
--label "org.opencontainers.image.source=https://github.com/${{ github.repository }}" \
--label "org.opencontainers.image.revision=$REVISION" \
--label "io.nvidia.nemoclaw.agent=$AGENT" \
--label "io.nvidia.nemoclaw.managed-image.contract=1" \
--label "io.nvidia.nemoclaw.managed-image.platform=linux/amd64" \
--label "io.nvidia.nemoclaw.managed-image.startup-profile=1" \
--label "io.nvidia.nemoclaw.managed-image.capabilities=1" \
--label "io.nvidia.nemoclaw.managed-image.cohort=$COHORT" \
--build-arg "BASE_IMAGE=$BASE_REFERENCE" \
--build-arg "NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION=1" \
--build-arg "NEMOCLAW_MANAGED_IMAGE_RUNTIME_USER=root" \
.

- name: Validate exact PR managed image contract
id: contract
shell: bash
Expand Down Expand Up @@ -569,14 +704,6 @@ jobs:
--image "$IMAGE_REFERENCE" \
--platform linux/amd64

- name: Log in to GHCR for exact same-repository PR digest
if: github.event.pull_request.head.repo.full_name == github.repository
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}

# Publish by digest only. No candidate tag, cohort tag, or release alias is
# created, so this proof cannot expose an incomplete all-agent cohort.
- name: Publish exact same-repository PR managed image by digest
Expand All @@ -598,7 +725,7 @@ jobs:
io.nvidia.nemoclaw.managed-image.capabilities=1
io.nvidia.nemoclaw.managed-image.cohort=ghrun-${{ github.run_id }}-${{ github.run_attempt }}
build-args: |
BASE_IMAGE=${{ steps.base.outputs.ref }}
BASE_IMAGE=${{ steps.candidate-base.outputs.ref || steps.candidate-base-local.outputs.ref || steps.base.outputs.ref }}
NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION=1
NEMOCLAW_MANAGED_IMAGE_RUNTIME_USER=root
cache-from: type=registry,ref=ghcr.io/nvidia/nemoclaw/${{ matrix.agent }}-sandbox:buildcache-linux-amd64
Expand Down
2 changes: 1 addition & 1 deletion agents/langchain-deepagents-code/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -227,7 +227,7 @@ RUN test -f /usr/local/bin/nemoclaw-managed-bootstrap \
&& cmp -s /usr/local/lib/nemoclaw/dcode-launcher.sh /usr/local/lib/nemoclaw/dcode-managed-exec \
&& chmod -R a+rX /opt/nemoclaw-blueprint \
&& test "$(find /opt/nemoclaw-deepagents-profile-plugin -type f -print | LC_ALL=C sort)" = "$(printf '%s\n' '/opt/nemoclaw-deepagents-profile-plugin/pyproject.toml' '/opt/nemoclaw-deepagents-profile-plugin/src/nemoclaw_deepagents_profile/__init__.py')" \
&& printf '%s %s\n' '8fe85c62293c74147848732dc56c33e8ab60133fa41c071da4328ac60f2bf44f' '/opt/nemoclaw-deepagents-profile-plugin/src/nemoclaw_deepagents_profile/__init__.py' '7ba7b77bd6f889cc861eddbe3e38fc1f4433a85b7bc2a9b516e19a19a37a7686' '/opt/nemoclaw-deepagents-profile-plugin/pyproject.toml' | sha256sum -c - \
&& printf '%s %s\n' '86b46958cd969407b05ce7ab10e711c7ad25375028a4c864f6f12519fe091ab3' '/opt/nemoclaw-deepagents-profile-plugin/src/nemoclaw_deepagents_profile/__init__.py' '5a07d4b473f2714021756eda005dceb6a0c7e6f3ff02ca4021d4debb8c170ff8' '/opt/nemoclaw-deepagents-profile-plugin/pyproject.toml' | sha256sum -c - \
&& /opt/venv/bin/pip3 install --no-index --no-cache-dir --no-deps --no-build-isolation /opt/nemoclaw-deepagents-profile-plugin \
&& /opt/venv/bin/python3 -I -c 'import nemoclaw_deepagents_profile; print("NEMOCLAW_DCODE_PROFILE_" + "IMPORT_GATE", flush=True); import deepagents; import deepagents_code' \
&& /opt/venv/bin/pip3 check \
Expand Down
2 changes: 1 addition & 1 deletion agents/langchain-deepagents-code/Dockerfile.base
Original file line number Diff line number Diff line change
Expand Up @@ -335,7 +335,7 @@ RUN python3 -m venv --copies "$VIRTUAL_ENV" \
-r /tmp/deepagents-code-requirements.lock \
&& "$VIRTUAL_ENV/bin/pip3" check \
&& "$VIRTUAL_ENV/bin/python3" -I -c \
"from importlib.metadata import version; expected = {'aiohttp': '3.14.3', 'cryptography': '50.0.0', 'deepagents-code': '0.1.34', 'langgraph-checkpoint-sqlite': '3.1.1', 'mcp': '1.28.1', 'pillow': '12.3.0', 'pyasn1': '0.6.4', 'uv': '0.11.33'}; actual = {name: version(name) for name in expected}; assert actual == expected, actual" \
"from importlib.metadata import version; expected = {'aiohttp': '3.14.3', 'cryptography': '50.0.0', 'deepagents-code': '0.1.54', 'langgraph-checkpoint-sqlite': '3.1.1', 'mcp': '1.28.1', 'pillow': '12.3.0', 'pyasn1': '0.6.4', 'uv': '0.11.33'}; actual = {name: version(name) for name in expected}; assert actual == expected, actual" \
&& ln -sf "$VIRTUAL_ENV/bin/dcode" /usr/local/bin/dcode \
&& ln -sf "$VIRTUAL_ENV/bin/deepagents-code" /usr/local/bin/deepagents-code \
&& rm -f /tmp/deepagents-code-requirements.lock \
Expand Down
4 changes: 2 additions & 2 deletions agents/langchain-deepagents-code/dcode-wrapper.sh
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ if [ "${1:-}" = "--nemoclaw-mcp-capability" ] && [ "$#" -eq 1 ]; then
exit 0
fi

unset BASH_ENV ENV OPENAI_PROXY
unset BASH_ENV ENV OPENAI_PROXY DEEPAGENTS_CODE_APPROVAL_MODE DEEPAGENTS_CODE_STARTUP_MODE
while IFS= read -r _nemoclaw_auto_approval_env; do
unset "$_nemoclaw_auto_approval_env"
done < <(compgen -A variable NEMOCLAW_DCODE_AUTO_APPROVAL || true)
Expand Down Expand Up @@ -637,7 +637,7 @@ try:
except Exception:
sys.exit(1)
# Schema pin: detection assumes a truthy top-level "credentials" key,
# matching the auth.json shape in deepagents-code==0.1.34. Nested or
# matching the auth.json shape reviewed for deepagents-code==0.1.54. Nested or
# renamed shapes ({"auth":{...}}, {"state":{"credentials":...}}, top-level
# list) are not detected. When bumping the upstream pin, re-review this
# assumption against the new auth.json schema.
Expand Down
Loading
Loading