Repository navigation
fix(e2e-exe-dev): never score a failure notice as a ping reply - #28
Merged
Merged
Conversation
A bad credential ended in PING: ok with REPLY "The agent run failed. Check the logs for details." because any non-empty reply counted. The headless installer (exe.dev, Proxmox, macOS) now records ping agent_failure (exit 2) when a session gets a new cli/local messages_out row marked failureNotice (nanocoai/nanoclaw#3908). When the runner may predate the marker (checkout without it, a pulled hardened image) or a DB cannot be read, the notice text and a reply starting "Error: " (pre-#3746) also count. exe-run.sh and proxmox-run.py refuse an empty, placeholder or non-sk-ant Anthropic credential before creating a VM or guest, except where a reused vault may not need it (--base, remote OneCLI); the installer checks the file right before handing it to the gateway. Values are never printed. Plugin 0.12.2.
nanocoai/nanoclaw#3980 makes chat.ts forward the failureNotice flag and exit 4 when a reply carried it. Without this case the installer recorded that as no_reply.
glifocat
marked this pull request as ready for review
October 1, 2026 16:00
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes?
The headless installer counted any non-empty ping reply as a pass. With a bad API key, NanoClaw answers the ping with its failure notice, and the run ended in:
Found during the nanocoai/nanoclaw#3901 r6 e2e on 2026-10-01. The cause there was an unfilled placeholder in the credential file.
Ping classification (
e2e-install.sh, shared by e2e-exe-dev headless, e2e-proxmox and e2e-macos):agent_failure(exit 2) when any session gets a newmessages_outrow tocli/local(whatchat.tsprints) markedfailureNotice. The runner sets that marker on every failure notice since fix(agent-runner): never answer a failure notice with another nanoclaw#3908. The CLI socket forwards only the text, so the installer reads the sessionoutbound.dbfiles read-only. Rows that existed before the ping are ignored, so reused checkouts work.chat.tsexit 4 is alsoagent_failure: since fix(setup): score the agent's failure notice as a failed first chat nanoclaw#3980 it forwards the flag and exits 4 for a flagged reply.Error:(cores before fix: preserve provider cancellation, failure delivery, and skill files nanoclaw#3746). "May predate the marker" means the checkout lacks it orNANOCLAW_HARDENED_IMAGE=truepulls an image.Credential check:
exe-run.shandproxmox-run.pyrefuse an empty or placeholder Anthropic credential file, or one without ansk-ant-value, before creating a VM or guest. The value is checked exactly as it is sent (only CR/LF removed) and is never printed.--baseor a remote OneCLI vault, the secret may already exist, so the host leaves the check to the installer. The installer checks the file only right before handing it to the gateway, so a reused vault with an unused placeholder file still passes.Plugin 0.12.2; CHANGELOG, catalog and the e2e-exe-dev SKILL.md are updated.
The same gap in nanoclaw's own setup ping is fixed separately in nanocoai/nanoclaw#3980.
Validation
python -m unittest discover -s tests(withskills/e2e-wizard/requirements.txtinstalled): 354 tests, one error. That error istest_payload_transport.test_alternate_owning_remote_transports_exact_selected_commit, which also fails on main.e2e-install.sh: notice text, late notice, the pre-#3746Error:reply, the marker with arbitrary text, and placeholder/foreign/embedded-space credentials. They pass with this change. Tests also cover: earlier and other-channel notices ignored, the marker trusted over quoted text, fallback when no DB is readable, hardened-image fallback (case-insensitive,.envand environment), a reused vault ignoring a placeholder file,--baseskipping the host check, and no VM or guest allocation on a bad credential.tests/test_repository_contracts.pypasses (version 0.12.2 in plugin.json, catalog and CHANGELOG).cli/localare whatchat.tsprints, so scoping is by channel.962d527c, installer from this branch at 5772a59 (2026-10-01):anthropic_api_keyfile): exit 66 before any VM was created; value not printed.STATUS: pass,PING: ok, real agent reply, VM removed by--rm(removal verified).ping: no_reply, not a pass. The SDK retried the 401s, so the runner's marked notice (cli/local,failureNotice: true) landed about 3 minutes after the ping, pastchat.ts's 120 s stop. Running this branch'sfailure_notice_idsagainst that VM's realoutbound.dbreturned the notice's id (exit 0). So the marker read works on a real install; the in-window path is covered by the offline tests. VM deleted after inspection.