nemoclaw-maintainer-e2e

作成者: nvidia

NemoClawメンテナー向けに信頼されたGitHub Actions E2Eをディスパッチし、検証します。E2Eスイートの実行、Launchable E2Eの実行、フル…の実行などのリクエストに使用します。

npx skills add https://github.com/nvidia/nemoclaw --skill nemoclaw-maintainer-e2e

Run Maintainer E2E

Use .github/workflows/e2e.yaml from trusted main. Do not substitute local live E2E unless the maintainer explicitly requests local execution.

Push runs publish Relevant E2E. Only a full manual run publishes Release qualification. That aggregate reports the full suite; it does not decide whether a tag can proceed. A generic E2E request does not authorize Exact staging Brev Launchable.

Route the Request

  • For E2E against a pull request revision, read and follow Manual PR Runs.
  • To dispatch ordinary, focused, exact staging Launchable, or full E2E on main, read and follow Main Runs and the Launchable boundary below.
  • For a release decision inspection, use the section below. Do not load a dispatch reference unless the maintainer requests a new run.

Exact Staging Brev Launchable Boundary

Exact staging Brev Launchable runs only for a trusted manual dispatch against main. Launchable mode selects only that job. Full mode adds it to the default E2E selection. The trusted workflow requires repository maintain or admin permission before the job's source checkout.

The job builds the exact candidate image, deploys the standing Launchable, and verifies all of these results before it succeeds:

  • environment access and the exact booted image;
  • the candidate SHA, image-repository SHA, baked checkout with no uncommitted changes, and absence of runtime overrides;
  • hosted and sandbox inference through the preinstalled full E2E suite; and
  • Brev workspace deletion and confirmed absence.

Exact staging Brev Launchable reads these credentials from repository Actions secrets:

  • BREV_API_KEY authenticates the trusted host-side Brev CLI for workspace operations in the organization identified by BREV_ORG_ID. Candidate code does not receive this API key.
  • NEMOCLAW_IMAGE_DISPATCH_TOKEN is exposed as GH_TOKEN only to the trusted host script. It grants Actions read/write access to brevdev/nemoclaw-image for workflow dispatch, run inspection, and artifact download.
  • NVIDIA_INFERENCE_API_KEY is exported into the Brev guest for the full E2E process. Code in the baked candidate checkout can read and use it.

brev login writes BREV_API_KEY and BREV_ORG_ID to $HOME/.brev/credentials.json on the GitHub-hosted runner. Later trusted steps and processes in that job can read the file. The workflow does not delete it explicitly. Runner teardown discards the ephemeral filesystem.

The credentials remain valid until they expire or an administrator revokes them in their issuing services. If cleanup fails, remove the recorded Brev workspace. Rotate or revoke each credential to remove later access.

The NEMOCLAW_STAGING_LAUNCHABLE_ID repository Actions variable selects the standing Launchable. Keep it equal to the Launchable ID in the default URL owned by nemoclaw-maintainer-validate-launchable.

A successful job retains launchable-e2e.json, full-e2e.log, and cleanup.json. The cleanup record exists only after the job confirms workspace absence. A preparation failure can produce no artifact. A later failure can retain only lane.log and the phase artifacts created before exit.

The job uses the staging-brev-launchable-cpu concurrency group without cancelling a running job. GitHub keeps at most one pending job in that group, so a newer job can replace an older pending job. A queued, waiting, or accepted dispatch is not a successful result.

Inspect the Newest Full Main Run

This mode is read-only. It does not dispatch a run.

List the newest identifiable full manual main run:

gh run list --repo NVIDIA/NemoClaw --workflow e2e.yaml \
  --event workflow_dispatch --branch main --limit 100 \
  --json databaseId,displayTitle,attempt,createdAt,startedAt,updatedAt,headSha,status,conclusion,url \
  --jq 'map(select(.displayTitle | startswith("E2E full main"))) | first'

Inspect Release qualification, Exact staging Brev Launchable, and every other job that is not successful:

gh run view <run-id> --attempt <attempt> --repo NVIDIA/NemoClaw \
  --json jobs --jq '[.jobs[] |
    select(.name == "Release qualification" or .name == "Exact staging Brev Launchable" or
      .status != "completed" or
      (.conclusion != null and .conclusion != "success")) |
    {name,status,conclusion,startedAt,completedAt,url}]'

If no named full run appears in the 100-run window, report that no recent identifiable full run was found. Runs created before this naming contract cannot be distinguished without scanning each run's jobs. Do not perform that legacy scan.

Dispatch and verify new PR and main runs only through the selected reference above. Those references own permission checks, selector validation, candidate resolution, correlation IDs, bounded run lookup, exact-SHA binding, result verification, credential boundaries, and resource cleanup. Do not reconstruct those commands here.

The PR reference also owns the native-runtime producer's first-attempt, ephemeral-runner, unprivileged account, Docker isolation, evidence, and cleanup requirements.

Report the Release Context

Return:

  • exact createdAt, startedAt, and updatedAt values, labeling updatedAt as last updated;
  • workflow attempt;
  • age at inspection time calculated from createdAt;
  • tested commit SHA;
  • workflow status, conclusion, and URL;
  • Release qualification status, conclusion, start, completion, and URL; and
  • failed, cancelled, skipped, or still-running jobs and their URLs.

When the caller provides a release candidate, state whether the tested commit matches it. Do not reject a different commit, impose a staleness threshold, or decide whether tagging can proceed.

Handoff

Return:

  • the mode and selectors;
  • the tested commit;
  • the result;
  • the workflow URL; and
  • relevant job URLs.

A focused run supplements the reported full-run status; it does not become a full run.

Do not ask for release confirmation or decide whether a release can proceed. The release-tag skill owns the general E2E decision and records any reason for proceeding with an exceptional general E2E status.

Access Failures

Follow the shared Git and GitHub Access Hard Stop.

nvidiaのその他のスキル

compileiq-debug
nvidia
何かがおかしいときに使用:Search()がハングする、すべての評価がINVALID_SCOREを返す、スコアが改善しない、すべての設定が同じ数値を返す、ptxasエラー…
create-github-pr
nvidia
gh CLIを使用してGitHubのプルリクエストを作成します。ユーザーが新しいPRを作成したい、コードをレビューに提出したい、またはプルリクエストを開きたい場合に使用します。トリガーキーワード -…
nemoclaw-maintainer-cross-issue-sweep
nvidia
他のオープンなIssueをスキャンし、特定のPRが修正する可能性があるものや、誤って壊す可能性があるものを見つけます。隣接修正の機会や矛盾リスクをfile:line…と共に出力します。
fhir-basics
nvidia
エージェントにFHIR R4 APIの動作方法、利用可能なリソース、検索パラメータを使ったクエリ方法、およびすべてのレスポンス形式を正しく解析する方法を教えます…
compileiq-validate-result
nvidia
検索が完了した後、かつスピードアップの申請やACFの発送の前に使用します。dump_results CSVを読み込み、トップK候補(単一目的)を抽出します…
changelog-audit
nvidia
リリース前にWarp CHANGELOG.mdを監査:失われたエントリを復元、ユーザー影響で並べ替え、エントリの文言を洗練、行折り返し、および(リリースブランチモードで)比較をバンプ…
maintain-dynamic-plugins
nvidia
NeMo Relayの動的プラグインローダー、マニフェスト、RustネイティブSDK、gRPCワーカープロトコル、PythonワーカーSDK、ドキュメント、テスト、およびリリースワークフローのカバレッジを維持する
dgx-diagnose
nvidia
一般的なDGX Station GB300の問題(CUDAクラッシュ、誤ったGPUターゲット、vLLM/SGLangコンテナのバグ、MIG状態の問題、NVLink/Fabric Managerエラーなど)を診断します。