Skip to content

Pin whitaker-installer 0.2.9 and refuse source builds - #164

Merged
leynos merged 2 commits into
mainfrom
jm5/whitaker-0-2-9-no-source-fallback
Sep 28, 2026
Merged

leynos merged 2 commits into
mainfrom
jm5/whitaker-0-2-9-no-source-fallback

Conversation

@leynos

@leynos leynos commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Summary

get-rust-tooling now installs whitaker-installer 0.2.9 by default and runs it with --no-source-fallback, so a missing published lint library or Dylint tool fails the install rather than being compiled from source. This follows the estate's Whitaker install rule (2026-09-24). 0.2.9 is the first release with the flag.

The script is a developer-environment bootstrap that CI never runs, and it is named as an exemption in concordat's whitaker-provisioning rule (QG-002). That exemption covers the provisioning route only: the script still pins the installer and refuses source builds.

Review walkthrough

Validation

make check-fmt, make lint, make typecheck, make markdownlint, make spelling and make test (765 passed) pass. make fmt reflows about forty unrelated Markdown files on main with the local formatter, so those changes were discarded rather than committed.

Summary by Sourcery

Pin Whitaker tooling to installer 0.2.9 or newer and make missing published assets fail safely without source builds.

Bug Fixes:

  • Prevent Whitaker installation from compiling missing published lint libraries or Dylint tools from source by enforcing the no-source-fallback behavior.

Enhancements:

  • Pin the default Whitaker installer version to 0.2.9 while preserving support for newer overrides and optional experimental tooling.
  • Document the updated Whitaker installation behavior, version requirements, and migration guidance.

Documentation:

  • Document the Whitaker provisioning policy in the developer guide, user guide, and v0.3.0 migration guide.

Tests:

  • Add process-level coverage for opt-in installation, version overrides, experimental options, download failures, and refused source builds.

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: 6e57ccfa-d134-4f61-8902-64002dea2207

📥 Commits

Reviewing files that changed from the base of the PR and between 0aca9ec and 54f3d24.

📒 Files selected for processing (2)
  • docs/users-guide.md
  • get-rust-tooling
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • leynos/cuprum (auto-detected)
  • leynos/typos-config-builder (auto-detected)
  • leynos/comenq (auto-detected)
  • leynos/cmd-mox (auto-detected)
  • leynos/ansible (auto-detected)

Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


  • Pin get-rust-tooling to Whitaker Installer 0.2.9 and pass --no-source-fallback when Whitaker is enabled. Fail installation when published lint-library or Dylint artifacts are missing instead of building them from source.
  • Keep --experimental conditional on WITH_WHITAKER_EXPERIMENTAL.
  • Document the installer version and source-fallback behaviour in docs/users-guide.md. Treat the bootstrap route as exempt from concordat’s whitaker-provisioning rule; retain the installer pin and source-build restriction.
  • The author reports that formatting, lint, typecheck, Markdown, spelling, and test checks passed, including 765 tests.

Walkthrough

The Whitaker installer now defaults to version 0.2.9 and passes --no-source-fallback when enabled. The user guide documents the flag, its effect when published tools are missing, and the minimum installer version that accepts it.

Changes

Whitaker installer behaviour

Layer / File(s) Summary
Installer defaults and documentation
get-rust-tooling, docs/users-guide.md
Set the default installer version to 0.2.9 and pass --no-source-fallback when Whitaker is enabled. Document the failure behaviour when published tools are missing and note that earlier installer versions reject the flag.

Priority: ⬇️ Low

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 54f3d

Whitaker remains opt-in. When enabled, it uses an installer version that supports the no-source-fallback option; missing published artifacts leave Whitaker unavailable with a warning rather than triggering a source build. No merge-blocking risk remains.


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (2 errors, 2 warnings)

Check name Status Explanation Resolution
Testing (Overall) ❌ Error The pull request changes get-rust-tooling behaviour, but it adds no tests. The diff changes the default WHITAKER_INSTALLER_VERSION to 0.2.9 and adds --no-source-fallback to the `whitaker-insta… Add substantive shell-level tests for get-rust-tooling. Mock the external commands and required setup so the script runs with WITH_WHITAKER=1. Assert that the default invocation installs whitaker-installer@0.2.9 and passes `--no-sourc…
Testing (Unit And Behavioural) ❌ Error The change alters externally observable command-line behaviour in get-rust-tooling, but the pull request adds no tests. Existing Rust entrypoint tests replace get-rust-tooling with a logging stub … Add a behavioural process-level test for get-rust-tooling at its command boundary. Stub rustup, cargo, whitaker-installer, and other external commands, then assert the default invocation uses whitaker-installer@0.2.9 and `--no-sou…
User-Facing Documentation ⚠️ Warning Add migration documentation for the changed Whitaker behaviour. get-rust-tooling now defaults to whitaker-installer 0.2.9 and passes --no-source-fallback; the users' guide documents this at `doc… Update docs/v0-3-0-migration-guide.md with a Whitaker migration section. Describe the previous source-build fallback, the new --no-source-fallback behaviour, the 0.2.9 minimum installer version, and the action required for users who set…
Developer Documentation ⚠️ Warning The pull request changes a tooling requirement without documenting it in docs/developers-guide.md. get-rust-tooling now defaults to whitaker-installer 0.2.9 and passes --no-source-fallback, wh… Update docs/developers-guide.md with the Whitaker provisioning contract. State the default WHITAKER_INSTALLER_VERSION as 0.2.9, require --no-source-fallback, describe the failure when published lint-library or Dylint assets are unav…
✅ Passed checks (11 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main changes: pin whitaker-installer to 0.2.9 and refuse source builds. No roadmap or GitHub issue number is required because the description does not reference one.
Description check ✅ Passed The description accurately explains the installer version change, --no-source-fallback, documentation updates, exemption scope, and validation results.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Module-Level Documentation ✅ Passed Pass the module-level documentation check. The changed module get-rust-tooling retains its top-level documentation, which states its purpose, the tooling it installs, and its relationship to the clo…
Testing (Property / Proof) ✅ Passed Treat this as PASS. The change adds a fixed --no-source-fallback argument, a default version, and one boolean-controlled --experimental branch in a shell script. The meaningful input space is smal…
Testing (Compile-Time / Ui) ✅ Passed Pass this check. The pull request changes a Bash bootstrap script and Markdown documentation only. It introduces no Rust or TypeScript compile-time behaviour, so trybuild or an equivalent test does no…
Unit Architecture ✅ Passed Pass this check. The diff changes only the Whitaker command path and its documentation. get-rust-tooling keeps installation and execution as explicit commands, passes --no-source-fallback, and che…
Domain Architecture ✅ Passed Pass this check. The pull request changes only get-rust-tooling and its user guide. The implementation remains a developer-tool bootstrap script that handles environment variables, filesystem paths,…
Observability ✅ Passed PASS — The change affects the developer-environment bootstrap, not a production service. It adds no throughput, latency, queue, retry, cache, or resource behaviour that needs metrics, and it adds no n…
Full details: Testing (Overall)

Explanation

The pull request changes get-rust-tooling behaviour, but it adds no tests. The diff changes the default WHITAKER_INSTALLER_VERSION to 0.2.9 and adds --no-source-fallback to the whitaker-installer invocation. The test tree contains no Whitaker-related tests, and neither changed file is a test file. Existing entrypoint tests do not execute get-rust-tooling or assert its Whitaker arguments. Therefore, the change is not guarded against plausible incorrect implementations such as retaining 0.2.6, omitting --no-source-fallback, or incorrectly handling WITH_WHITAKER_EXPERIMENTAL.

Resolution

Add substantive shell-level tests for get-rust-tooling. Mock the external commands and required setup so the script runs with WITH_WHITAKER=1. Assert that the default invocation installs whitaker-installer@0.2.9 and passes --no-source-fallback. Assert that WHITAKER_INSTALLER_VERSION overrides the default. Assert that --experimental is added only when WITH_WHITAKER_EXPERIMENTAL is enabled. Test the no-Whitaker path to ensure the installer is not invoked. Test command failure handling if that behaviour remains part of the script contract. Test the local argument construction and invocation only; do not test the third-party tool's internal behaviour.

Full details: User-Facing Documentation

Explanation

Add migration documentation for the changed Whitaker behaviour. get-rust-tooling now defaults to whitaker-installer 0.2.9 and passes --no-source-fallback; the users' guide documents this at docs/users-guide.md:732-774. However, the required n+1 migration guide, docs/v0-3-0-migration-guide.md, has no Whitaker entry, and no migration document changed in this pull request.

Resolution

Update docs/v0-3-0-migration-guide.md with a Whitaker migration section. Describe the previous source-build fallback, the new --no-source-fallback behaviour, the 0.2.9 minimum installer version, and the action required for users who set WHITAKER_INSTALLER_VERSION or rely on source builds. State that a missing published lint library or Dylint tool causes the Whitaker installation command to fail; the script then emits its existing warning.

Full details: Developer Documentation

Explanation

The pull request changes a tooling requirement without documenting it in docs/developers-guide.md. get-rust-tooling now defaults to whitaker-installer 0.2.9 and passes --no-source-fallback, which makes missing published Whitaker or Dylint assets fail instead of triggering source builds. The pull request documents this only in docs/users-guide.md; the developer guide has no Whitaker or get-rust-tooling requirement. This is a direct documentation gap for the changed bootstrap tooling requirement.

Resolution

Update docs/developers-guide.md with the Whitaker provisioning contract. State the default WHITAKER_INSTALLER_VERSION as 0.2.9, require --no-source-fallback, describe the failure when published lint-library or Dylint assets are unavailable, and document the conditional --experimental flag. Record the estate decision in an appropriate ADR or design document if this policy is treated as an architectural decision.

Full details: Testing (Unit And Behavioural)

Explanation

The change alters externally observable command-line behaviour in get-rust-tooling, but the pull request adds no tests. Existing Rust entrypoint tests replace get-rust-tooling with a logging stub and do not execute the changed script. No test verifies the default 0.2.9 pin, --no-source-fallback, conditional --experimental, or the missing-artifact error path.

Resolution

Add a behavioural process-level test for get-rust-tooling at its command boundary. Stub rustup, cargo, whitaker-installer, and other external commands, then assert the default invocation uses whitaker-installer@0.2.9 and --no-source-fallback, the experimental flag is added only when WITH_WHITAKER_EXPERIMENTAL is enabled, an overridden installer version is honoured, and a failed published-tool installation follows the intended error path without a source build. Keep the test isolated from real package managers, network access, and the real home directory.


Whitaker sets out with a newer key
No source fallback shapes the journey
Missing tools now stop the install
The guide records the version call
One clear flag keeps the path in view

Comment @coderabbitai help to get the list of available commands.

@sourcery-ai

sourcery-ai Bot commented Sep 24, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Whitaker provisioning now defaults to whitaker-installer 0.2.9 and passes --no-source-fallback, ensuring missing published artifacts fail installation rather than triggering source builds; the user guide documents the behavior and version requirement.

Sequence diagram for Whitaker installation without source fallback

sequenceDiagram
    participant Bootstrap as get-rust-tooling
    participant Installer as whitaker-installer_0_2_9
    participant Registry as Published_artifacts

    Bootstrap->>Installer: install --no-source-fallback
    Installer->>Registry: fetch published lint library or Dylint tool
    alt artifact available
        Registry-->>Installer: published artifact
        Installer-->>Bootstrap: installation succeeds
    else artifact missing
        Registry-->>Installer: artifact unavailable
        Installer-->>Bootstrap: installation fails
    end
Loading

File-Level Changes

Change Details Files
Pin the Whitaker installer to a release that supports disabling source fallback and document the required version.
  • Change the default installer version from 0.2.6 to 0.2.9.
  • Document that 0.2.9 or later is required for the new installer flag.
get-rust-tooling
docs/users-guide.md
Make Whitaker provisioning fail when published artifacts are unavailable instead of building them from source.
  • Pass --no-source-fallback to whitaker-installer.
  • Clarify the failure behavior and its effect on lint libraries and Dylint tools.
get-rust-tooling
docs/users-guide.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@leynos
leynos marked this pull request as ready for review September 25, 2026 05:37
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @leynos, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 3 days and 10 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pre-merge checks failed. Please resolve the failing checks before merging.

`get-rust-tooling` installed whitaker-installer 0.2.6 and let it compile
the lint suite or the Dylint tools from source whenever a published
asset was missing. The estate's Whitaker install rule (2026-09-24)
forbids that: the installer runs with `--no-source-fallback`, so a
missing asset fails the install instead.

0.2.9 is the first release with the flag, so it is the new default.
`--experimental` is still appended when `WITH_WHITAKER_EXPERIMENTAL` is
set. This developer-environment script is named as an exemption in
concordat's whitaker-provisioning rule, since CI never runs it; the
exemption covers the provisioning route, not these two clauses.
The review asked for tests at the command boundary and for the change
to be documented for users and developers.

- The Whitaker block in `get-rust-tooling` becomes
  `install_whitaker_tooling`, called once, so it can be driven alone.
- `tests/test_get_rust_tooling_whitaker.py` extracts the function and
  runs it with stubbed `cargo` and `whitaker-installer`: nothing runs
  without `WITH_WHITAKER`; the default installs 0.2.9 and passes
  `--no-source-fallback`; an overridden version is honoured;
  `--experimental` follows its flag; a failed download warns and skips
  the installer; a refused install warns and builds nothing. Six
  mutations of the script each fail a test.
- The developers' guide records the contract and why this script is an
  exemption to the CI provisioning rule; the v0.3.0 migration guide
  says what changed and what to do about a pinned older version.
@leynos
leynos force-pushed the jm5/whitaker-0-2-9-no-source-fallback branch from 54f3d24 to ce34efc Compare September 26, 2026 17:01
@leynos

leynos commented Sep 26, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai The head is now ce34efc, and it answers the earlier table. Could you confirm whether anything still blocks it?

  • The Whitaker block in get-rust-tooling is now install_whitaker_tooling, called once.
  • tests/test_get_rust_tooling_whitaker.py extracts that function and runs it with stubbed cargo and whitaker-installer. It checks that nothing runs without WITH_WHITAKER, that the default installs whitaker-installer@0.2.9 and passes --no-source-fallback, that an overridden version is honoured, and that --experimental follows its flag. It also checks that a failed download warns and skips the installer, and that a refused install warns and builds nothing.
  • docs/developers-guide.md has a "get-rust-tooling Whitaker install" section, and docs/v0-3-0-migration-guide.md has a "Whitaker installs refuse source builds" section.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail
printf '%s\n' 'HEAD:'
git rev-parse HEAD
printf '%s\n' 'PR metadata:'
gh pr view 164 --repo leynos/agent-helper-scripts --json headRefOid,baseRefName,state,mergeable,statusCheckRollup --jq '{headRefOid,baseRefName,state,mergeable,statusCheckRollup:[.statusCheckRollup[]?|{name,conclusion,status}]}'
printf '%s\n' 'Relevant file locations:'
fd -a '^(get-rust-tooling|test_get_rust_tooling_whitaker\.py|developers-guide\.md|v0-3-0-migration-guide\.md|users-guide\.md)$'
printf '%s\n' 'Outline of Python tests:'
ast-grep outline tests/test_get_rust_tooling_whitaker.py --items all || true
printf '%s\n' 'Implementation matches:'
rg -n -C8 'install_whitaker_tooling|WHITAKER_INSTALLER_VERSION|WITH_WHITAKER|no-source-fallback' get-rust-tooling
printf '%s\n' 'Test content:'
sed -n '1,270p' tests/test_get_rust_tooling_whitaker.py
printf '%s\n' 'Documentation references:'
rg -n -C8 'get-rust-tooling.*Whitaker install|Whitaker installs refuse source builds|no-source-fallback|WHITAKER_INSTALLER_VERSION' docs/developers-guide.md docs/v0-3-0-migration-guide.md docs/users-guide.md
printf '%s\n' 'Review thread context:'
gh api repos/leynos/agent-helper-scripts/pulls/164/comments --paginate --jq '.[] | select(.user.login=="coderabbitai" or .user.login=="leynos") | {id,path,line,body,commit_id,in_reply_to_id}' | tail -c 18000

Length of output: 17210


🏁 Script executed:

#!/bin/bash
set -euo pipefail
printf '%s\n' 'PR diff stat and patch:'
gh pr diff 164 --repo leynos/agent-helper-scripts --stat || true
gh pr diff 164 --repo leynos/agent-helper-scripts | head -c 47000
printf '\n%s\n' 'PR issue comments:'
gh api repos/leynos/agent-helper-scripts/issues/164/comments --paginate --jq '.[] | {user:.user.login,body,created_at}' | tail -c 22000
printf '\n%s\n' 'Reviews:'
gh api repos/leynos/agent-helper-scripts/pulls/164/reviews --paginate --jq '.[] | {user:.user.login,state,body,commit_id}' | tail -c 14000
printf '\n%s\n' 'Whitaker documentation excerpt:'
sed -n '220,244p' docs/developers-guide.md
printf '\n%s\n' 'Script setup and surrounding context:'
sed -n '1,65p;120,165p' get-rust-tooling

Length of output: 41844


🏁 Script executed:

#!/bin/bash
set -euo pipefail
gh pr view 164 --repo leynos/agent-helper-scripts --json headRefOid,mergeable,mergeStateStatus,reviewDecision,isDraft,latestReviews,statusCheckRollup --jq '{headRefOid,mergeable,mergeStateStatus,reviewDecision,isDraft,latestReviews:[.latestReviews[]?|{author:.author.login,state,submittedAt}],statusCheckRollup:[.statusCheckRollup[]?|{typename:.__typename,name,conclusion,status}]}'

Length of output: 1466


@leynos, the earlier testing and documentation findings are addressed at ce34efc4. I found no remaining code blocker from that review.

The review decision still blocks approval: GitHub reports CHANGES_REQUESTED from my earlier review, even though the PR’s merge state is CLEAN. My earlier statement that the PR was mergeable did not account for that review decision. Request an updated review to clear it; do not treat the successful Makefile gate as clearance of the review.

You are interacting with an AI system.

@leynos
leynos merged commit 10cb676 into main Sep 28, 2026
6 checks passed
@leynos
leynos deleted the jm5/whitaker-0-2-9-no-source-fallback branch September 28, 2026 09:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant