Pin whitaker-installer 0.2.9 and refuse source builds - #164
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Team Run ID: 📒 Files selected for processing (2)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.
WalkthroughThe Whitaker installer now defaults to version 0.2.9 and passes ChangesWhitaker installer behaviour
Priority: ⬇️ Low Change: Bug fix Merge Risk: ⚪ Minimal · up to Whitaker remains opt-in. When enabled, it uses an installer version that supports the no-source-fallback option; missing published artifacts leave Whitaker unavailable with a warning rather than triggering a source build. No merge-blocking risk remains. Caution Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional.
❌ Failed checks (2 errors, 2 warnings)
✅ Passed checks (11 passed)
Full details: Testing (Overall)Explanation The pull request changes Resolution Add substantive shell-level tests for Full details: User-Facing DocumentationExplanation Add migration documentation for the changed Whitaker behaviour. Resolution Update Full details: Developer DocumentationExplanation The pull request changes a tooling requirement without documenting it in Resolution Update Full details: Testing (Unit And Behavioural)Explanation The change alters externally observable command-line behaviour in Resolution Add a behavioural process-level test for Whitaker sets out with a newer key Comment |
Reviewer's guide (collapsed on small PRs)Reviewer's GuideWhitaker provisioning now defaults to whitaker-installer 0.2.9 and passes --no-source-fallback, ensuring missing published artifacts fail installation rather than triggering source builds; the user guide documents the behavior and version requirement. Sequence diagram for Whitaker installation without source fallbacksequenceDiagram
participant Bootstrap as get-rust-tooling
participant Installer as whitaker-installer_0_2_9
participant Registry as Published_artifacts
Bootstrap->>Installer: install --no-source-fallback
Installer->>Registry: fetch published lint library or Dylint tool
alt artifact available
Registry-->>Installer: published artifact
Installer-->>Bootstrap: installation succeeds
else artifact missing
Registry-->>Installer: artifact unavailable
Installer-->>Bootstrap: installation fails
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
`get-rust-tooling` installed whitaker-installer 0.2.6 and let it compile the lint suite or the Dylint tools from source whenever a published asset was missing. The estate's Whitaker install rule (2026-09-24) forbids that: the installer runs with `--no-source-fallback`, so a missing asset fails the install instead. 0.2.9 is the first release with the flag, so it is the new default. `--experimental` is still appended when `WITH_WHITAKER_EXPERIMENTAL` is set. This developer-environment script is named as an exemption in concordat's whitaker-provisioning rule, since CI never runs it; the exemption covers the provisioning route, not these two clauses.
The review asked for tests at the command boundary and for the change to be documented for users and developers. - The Whitaker block in `get-rust-tooling` becomes `install_whitaker_tooling`, called once, so it can be driven alone. - `tests/test_get_rust_tooling_whitaker.py` extracts the function and runs it with stubbed `cargo` and `whitaker-installer`: nothing runs without `WITH_WHITAKER`; the default installs 0.2.9 and passes `--no-source-fallback`; an overridden version is honoured; `--experimental` follows its flag; a failed download warns and skips the installer; a refused install warns and builds nothing. Six mutations of the script each fail a test. - The developers' guide records the contract and why this script is an exemption to the CI provisioning rule; the v0.3.0 migration guide says what changed and what to do about a pinned older version.
54f3d24 to
ce34efc
Compare
|
@coderabbitai The head is now ce34efc, and it answers the earlier table. Could you confirm whether anything still blocks it?
|
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' 'HEAD:'
git rev-parse HEAD
printf '%s\n' 'PR metadata:'
gh pr view 164 --repo leynos/agent-helper-scripts --json headRefOid,baseRefName,state,mergeable,statusCheckRollup --jq '{headRefOid,baseRefName,state,mergeable,statusCheckRollup:[.statusCheckRollup[]?|{name,conclusion,status}]}'
printf '%s\n' 'Relevant file locations:'
fd -a '^(get-rust-tooling|test_get_rust_tooling_whitaker\.py|developers-guide\.md|v0-3-0-migration-guide\.md|users-guide\.md)$'
printf '%s\n' 'Outline of Python tests:'
ast-grep outline tests/test_get_rust_tooling_whitaker.py --items all || true
printf '%s\n' 'Implementation matches:'
rg -n -C8 'install_whitaker_tooling|WHITAKER_INSTALLER_VERSION|WITH_WHITAKER|no-source-fallback' get-rust-tooling
printf '%s\n' 'Test content:'
sed -n '1,270p' tests/test_get_rust_tooling_whitaker.py
printf '%s\n' 'Documentation references:'
rg -n -C8 'get-rust-tooling.*Whitaker install|Whitaker installs refuse source builds|no-source-fallback|WHITAKER_INSTALLER_VERSION' docs/developers-guide.md docs/v0-3-0-migration-guide.md docs/users-guide.md
printf '%s\n' 'Review thread context:'
gh api repos/leynos/agent-helper-scripts/pulls/164/comments --paginate --jq '.[] | select(.user.login=="coderabbitai" or .user.login=="leynos") | {id,path,line,body,commit_id,in_reply_to_id}' | tail -c 18000Length of output: 17210 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' 'PR diff stat and patch:'
gh pr diff 164 --repo leynos/agent-helper-scripts --stat || true
gh pr diff 164 --repo leynos/agent-helper-scripts | head -c 47000
printf '\n%s\n' 'PR issue comments:'
gh api repos/leynos/agent-helper-scripts/issues/164/comments --paginate --jq '.[] | {user:.user.login,body,created_at}' | tail -c 22000
printf '\n%s\n' 'Reviews:'
gh api repos/leynos/agent-helper-scripts/pulls/164/reviews --paginate --jq '.[] | {user:.user.login,state,body,commit_id}' | tail -c 14000
printf '\n%s\n' 'Whitaker documentation excerpt:'
sed -n '220,244p' docs/developers-guide.md
printf '\n%s\n' 'Script setup and surrounding context:'
sed -n '1,65p;120,165p' get-rust-toolingLength of output: 41844 🏁 Script executed: #!/bin/bash
set -euo pipefail
gh pr view 164 --repo leynos/agent-helper-scripts --json headRefOid,mergeable,mergeStateStatus,reviewDecision,isDraft,latestReviews,statusCheckRollup --jq '{headRefOid,mergeable,mergeStateStatus,reviewDecision,isDraft,latestReviews:[.latestReviews[]?|{author:.author.login,state,submittedAt}],statusCheckRollup:[.statusCheckRollup[]?|{typename:.__typename,name,conclusion,status}]}'Length of output: 1466
The review decision still blocks approval: GitHub reports You are interacting with an AI system. |
Summary
get-rust-toolingnow installs whitaker-installer 0.2.9 by default and runs it with--no-source-fallback, so a missing published lint library or Dylint tool fails the install rather than being compiled from source. This follows the estate's Whitaker install rule (2026-09-24). 0.2.9 is the first release with the flag.The script is a developer-environment bootstrap that CI never runs, and it is named as an exemption in concordat's
whitaker-provisioningrule (QG-002). That exemption covers the provisioning route only: the script still pins the installer and refuses source builds.Review walkthrough
WITH_WHITAKERandWHITAKER_INSTALLER_VERSION.Validation
make check-fmt,make lint,make typecheck,make markdownlint,make spellingandmake test(765 passed) pass.make fmtreflows about forty unrelated Markdown files on main with the local formatter, so those changes were discarded rather than committed.Summary by Sourcery
Pin Whitaker tooling to installer 0.2.9 or newer and make missing published assets fail safely without source builds.
Bug Fixes:
Enhancements:
Documentation:
Tests: