Skip to content

fix(release): install verified cargo-binstall binary directly - #5203

Open
ktechmidas wants to merge 1 commit into
v5.0-devfrom
ci/binstall-direct-verified-20260929
Open

ktechmidas wants to merge 1 commit into
v5.0-devfrom
ci/binstall-direct-verified-20260929

Conversation

@ktechmidas

@ktechmidas ktechmidas commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Issue being fixed or feature implemented

Release run36578531919 / Drive AMD64 job109440350081 failed in Docker dependency setup, not Platform source: the already-downloaded cargo-binstall1.10.11 was used to reinstall itself. A prebuilt lookup timeout fell back to an unlocked source compilation with newer incompatible binstalk dependencies (14 compiler errors).

What was done?

  • Install the downloaded binary directly into CARGO_HOME/bin; remove the redundant self-install/source-fallback path.
  • Pin SHA256 for both original1.10.11 AMD64 and ARM64 release archives and verify before extraction.
  • Use bounded HTTPS download retries, explicit extraction ownership, and verify the installed version.
  • Keep the tool version, downstream --locked tool installation, application sources and tests unchanged. One Dockerfile only.

How Has This Been Tested?

  • Downloaded both official release archives over HTTPS, checked SHA256 and archive member paths.
  • Executed the exact patched installation block in an isolated2CPU/2GiB container with real Cargo on an existing immutable runner image: checksum verification and installed1.10.11 version both passed. The initial harness lacked Cargo access under cap-dropALL; corrected only the disposable harness with DAC_OVERRIDE, no production runner changed.
  • Shell syntax and git diff --check pass. ARM64 archive verified, ARM64 execution and complete application image builds remain for hosted CI; no claim these are already green.
  • Does not change the existing beta7 tag/workflow snapshot or cancel/retry its jobs. Current manually requested attempt2 remains untouched.

Breaking Changes

None. Same pinned tool version; bootstrap download failure now fails directly instead of switching dependency resolution strategy.

Checklist:

  • Self-reviewed scoped change
  • Commented the non-obvious bootstrap failure
  • Real isolated install verification
  • Hosted checks and independent review complete

Prepared by infraclaw using latte's authorized internal-branch/PAT route. Account attribution is not a personal review or approval by latte.

PR Hygiene · f8fee0b

  • Bots — coderabbitai ✓ · thepastaclaw ✓
  • Self-review — post /self-reviewed
  • Within your 5 open PRs
  • Build green
  • Approvals
    • files with no dedicated owner (Dockerfile) — QuantumExplorer or shumkov

When every box is checked the PR Hygiene check passes and this can merge.

Summary by CodeRabbit

  • Reliability
    • Downloads of cargo-binstall archives now retry on failure and have timeout limits.
    • The archive checksum and installed version are verified before installation is considered successful.
    • Unsupported architectures continue to produce an error.

Additional native ARM64 validation — 2026-09-29 16:37 UTC

infraclaw verification update (not a personal review/approval by the protected transport account):

  • Native Linux aarch64 execution now passed, not QEMU and not an archive-only check. The unchanged cargo-binstall RUN body was extracted from Dockerfile blob 147093ca4bcc3df5e77d0e47501548444cc63711, which is identical across fix(release): install verified cargo-binstall binary directly #5203/fix(release): install verified cargo-binstall binary directly #5204/fix(release): install verified cargo-binstall binary directly #5205. The architecture-selected official archive passed its embedded SHA-256 check; extraction/direct installation succeeded; the exact final cargo binstall -V | grep -Fx "${BINSTALL_VERSION}" returned 1.10.11, exit 0.
  • The temporary, unregistered container used existing immutable ARM64 image sha256:2ef7934f6877b4b78bdc3d4b81c07ee260d1648c0338c86145cec02760390a24, nonroot UID/GID 1001, 1 CPU, 512 MiB, 64 PIDs, read-only root, temporary writable filesystems, drop-all capabilities and no-new-privileges. No CI token, secret mount, Docker socket, device or persistent volume was supplied. The container is absent afterward; no volumes were created. The ordinary worker's ID/image/start time/resource limits/restart count are unchanged.
  • The first synthetic harness attempt used UID 0 with all capabilities dropped and could not access the image's user-owned Cargo path; its downloaded archive verified and it cleaned up. Only the disposable harness was corrected to the image's intended nonroot identity. No Dockerfile, runner or workflow was changed for the passing proof.
  • Together with the previous AMD64 install check, this covers native installation/version checks on both architectures. It is not a full multi-stage Platform image build, application/test result, or replacement for the normal independent review/PR Hygiene gates. The PR's normal Docker jobs were skipped; that limitation remains explicit. No release retry, retag or publication was performed.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: dashpay/platform/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: d7759a49-c37c-4e75-8c69-6c049defc147

📥 Commits

Reviewing files that changed from the base of the PR and between 50d1203 and f8fee0b.

📒 Files selected for processing (1)
  • Dockerfile

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The Dockerfile now selects an architecture-specific SHA-256 checksum, verifies the downloaded cargo-binstall archive, installs the binary into CARGO_HOME/bin, and checks that its reported version matches BINSTALL_VERSION.

Changes

cargo-binstall installation

Layer / File(s) Summary
Verified download and installation
Dockerfile
The amd64 and arm64 branches set archive checksums. The Dockerfile downloads the archive with retry and timeout limits, verifies it, extracts only the binary, installs it into CARGO_HOME/bin, removes the temporary directory, and checks the exact version.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to f8fee

The version check and archive hashes match the inspected release artifacts. No concrete merge-blocking risk remains; normal ARM64 and full-image CI validation is still appropriate.

Security Architecture Review

Security architecture risk: 🔵 Low · up to f8fee

The new checksum gate reduces supply-chain exposure, and no introduced security finding was established. Residual risk remains because the build executes an externally sourced tool, while complete multi-architecture image validation is pending.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The relevant exposure is the container build: the installed binary runs in a secret-mounted step and later supplies downstream tool installation. The change strengthens the archive gate without expanding that step's mounted secret authority.

Trust Boundaries and Controls

  • observed — Downloaded release bytes cannot reach extraction or installation unless they match the architecture-selected digest embedded in the Dockerfile. The version check follows installation and precedes downstream use.

Resilience and Maintainability Implications

  • inferred — A partial download or interrupted provisioning step cannot authorize the next build step through this RUN; cleanup after abrupt interruption is not established for an abandoned transient build container.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: installing a verified cargo-binstall binary directly during release builds.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added this to the v4.2.0 milestone Sep 29, 2026
@thepastaclaw

thepastaclaw commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

⚠️ DEGRADED — Final review complete — no blockers (commit f8fee0b) · triage: low · Phase 2 only (queue backlog) · stand-in models (primary models out of quota)

@github-actions github-actions Bot added the waiting-bots Waiting for the review bots to report on this head label Sep 29, 2026
@ktechmidas ktechmidas changed the title fix(ci): install verified cargo-binstall binary directly fix(release): install verified cargo-binstall binary directly Sep 29, 2026
@ktechmidas
ktechmidas requested a review from shumkov September 29, 2026 16:07
@ktechmidas

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

infraclaw requesting one ordinary included review of exact head f8fee0b29313e97840ce6a67fa335e90b5da7301 after checking fresh allowance receipts. The existing successful CodeRabbit status explicitly means rate-limited, not reviewed.

One Dockerfile only: checksum-verified direct installation of the same cargo-binstall1.10.11 removes the redundant self-install and unlocked source fallback. Both official archives have checksum/member verification, and the exact patched AMD64 install/version check passed in an isolated container. The ordinary Docker CI job was skipped: this is NOT a full application-image build or ARM64 execution claim. Application code/tests, contributor branches, release tags and running jobs are unchanged.

Normal independent reviews and PR Hygiene gates remain binding; no self-approval, premium/priority request or bypass. This is infraclaw's request using the authorized protected transport, not the account owner's personal review or approval.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ DEGRADED — Final validation — Phase 2 only (queue backlog)

⚠️ DEGRADED review. The primary review models were unavailable (gpt-6-astra unavailable: Request rejected (429) · All credentials for model gpt-6-astra are cooling down (last error: usage_limit_reached: The us), so this review ran on stand-in models: gpt-5.6-luna → muse-spark-1.3-contributor, gpt-5.6-sol → muse-spark-1.3-contributor, gpt-5.6-terra → muse-spark-1.3-contributor, gpt-6-astra → muse-spark-1.3-contributor. Both review phases and the independent verifiers still ran, but on weaker models, with Phase 1 capped at high effort. Treat the verdict as provisional; a full-strength re-review will run on the next push once the primary models are back.

Dockerfile-only bootstrap fix is correct as written. Both Phase-2 claims were empirically refuted against the exact base image and official release archives: cargo-binstall -V prints a bare version that the grep gate matches, and BusyBox tar accepts --no-same-owner. No in-scope issues remain.

Review provenance

Source: reviewer 1: muse-spark-1.3-contributor (standing in for gpt-6-astra) (agent: phase2-reviewer, role: general); reviewer 2: muse-spark-1.3-contributor (standing in for gpt-6-astra) (agent: phase2-reviewer, role: architecture-layering); reviewer 3: muse-spark-1.3-contributor (standing in for gpt-6-astra) (agent: phase2-reviewer, role: security-auditor); final verifier: muse-spark-1.3-contributor (standing in for gpt-6-astra) (agent: astra-verifier, role: final-verifier)

  • Degraded mode: gpt-6-astra unavailable: Request rejected (429) · All credentials for model gpt-6-astra are cooling down (last error: usage_limit_reached: The us (detected by probe, since 2026-09-29T17:13:01Z); stand-ins gpt-5.6-luna → muse-spark-1.3-contributor, gpt-5.6-sol → muse-spark-1.3-contributor, gpt-5.6-terra → muse-spark-1.3-contributor, gpt-6-astra → muse-spark-1.3-contributor; Phase 1 effort capped at high
  • Triage: low by muse-spark-1.3-contributor (standing in for gpt-6-astra) (effort low) — Dockerfile-only bootstrap fix pins and verifies cargo-binstall with retries, a small contained build reliability change.
  • Phase 1 reviewers: not run (skipped for throughput: 11 PRs queued, above the 10 limit)
  • Fresh verifier: muse-spark-1.3-contributor (standing in for gpt-6-astra) — final-verifier; agent astra-verifier
  • Phase 2 reviewers: muse-spark-1.3-contributor (standing in for gpt-6-astra) — general (completed, effort medium); agent phase2-reviewer, muse-spark-1.3-contributor (standing in for gpt-6-astra) — architecture-layering (completed, effort medium); agent phase2-reviewer, muse-spark-1.3-contributor (standing in for gpt-6-astra) — security-auditor (completed, effort medium); agent phase2-reviewer

@github-actions

Copy link
Copy Markdown
Contributor

Bots are done — your move: post /self-reviewed.
Full checklist in the description.

@github-actions github-actions Bot added waiting-self-review Waiting for the author to post /self-reviewed and removed waiting-bots Waiting for the review bots to report on this head labels Sep 29, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

waiting-self-review Waiting for the author to post /self-reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants