fix(release): install verified cargo-binstall binary directly - #5204
ktechmidas wants to merge 1 commit into
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: dashpay/platform/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
|
thepastaclaw
left a comment
There was a problem hiding this comment.
⚠️ DEGRADED — Final validation — Phase 2 only (queue backlog)
⚠️ DEGRADED review. The primary review models were unavailable (gpt-6-astraunavailable: Request rejected (429) · All credentials for model gpt-6-astra are cooling down (last error: usage_limit_reached: The us), so this review ran on stand-in models:gpt-5.6-luna→muse-spark-1.3-contributor,gpt-5.6-sol→muse-spark-1.3-contributor,gpt-5.6-terra→muse-spark-1.3-contributor,gpt-6-astra→muse-spark-1.3-contributor. Both review phases and the independent verifiers still ran, but on weaker models, with Phase 1 capped athigheffort. Treat the verdict as provisional; a full-strength re-review will run on the next push once the primary models are back.
Dockerfile-only bootstrap fix replaces the redundant cargo-binstall self-reinstall with a checksum-verified direct binary install for both amd64 and arm64. SHA pinning, bounded HTTPS retries, and the trailing version gate are all correct, with no protocol, storage, or dependency-boundary impact.
Review provenance
Source: reviewer 1: muse-spark-1.3-contributor (standing in for gpt-6-astra) (agent: phase2-reviewer, role: general); reviewer 2: muse-spark-1.3-contributor (standing in for gpt-6-astra) (agent: phase2-reviewer, role: architecture-layering); final verifier: muse-spark-1.3-contributor (standing in for gpt-6-astra) (agent: astra-verifier, role: final-verifier)
- Degraded mode:
gpt-6-astraunavailable: Request rejected (429) · All credentials for model gpt-6-astra are cooling down (last error: usage_limit_reached: The us (detected by probe, since 2026-09-29T17:13:01Z); stand-insgpt-5.6-luna→muse-spark-1.3-contributor,gpt-5.6-sol→muse-spark-1.3-contributor,gpt-5.6-terra→muse-spark-1.3-contributor,gpt-6-astra→muse-spark-1.3-contributor; Phase 1 effort capped athigh - Triage:
lowbymuse-spark-1.3-contributor(standing in forgpt-6-astra) (effort low) — One-file Dockerfile-only build fix pinning the verified binary with no application logic change. - Phase 1 reviewers: not run (skipped for throughput: 11 PRs queued, above the 10 limit)
- Fresh verifier:
muse-spark-1.3-contributor(standing in forgpt-6-astra) — final-verifier; agentastra-verifier - Phase 2 reviewers:
muse-spark-1.3-contributor(standing in forgpt-6-astra) — general (completed, effort medium); agentphase2-reviewer,muse-spark-1.3-contributor(standing in forgpt-6-astra) — architecture-layering (completed, effort medium); agentphase2-reviewer
|
Bots are done — your move: post |
Issue being fixed or feature implemented
Same release bootstrap defect as #5203: cargo-binstall1.10.11 downloaded a prebuilt binary, then redundantly reinstalled itself; a GitHub timeout caused an unlocked, incompatible source fallback.
What was done?
Propagate the identical, checksum-verified direct install to
v4.3-dev. The source Dockerfile was byte-for-byte identical to v4.2 (blob6984e3ad); the repaired Dockerfile is also identical (blob147093ca). One file only, no application history or contributor branch changes.How Has This Been Tested?
Both official archives downloaded and checksum/member checks passed. Exact repaired installation block executed in an isolated2CPU/2GiB AMD64 container with real Cargo: version1.10.11 verified. Reused that evidence because source and result blobs are identical across all three branches. Shell syntax and diff checks pass. ARM64 binary execution/full application image builds are not claimed complete; normal hosted CI/review remains required.
Breaking Changes
None. Removes the unintended self-compilation path. Existing release tags are unchanged and no workflow rerun/publication is requested.
Checklist
Prepared by infraclaw with the authorized internal-branch/PAT route; account attribution is not a personal approval.
Additional native ARM64 validation — 2026-09-29 16:37 UTC
infraclaw verification update (not a personal review/approval by the protected transport account):
147093ca4bcc3df5e77d0e47501548444cc63711, which is identical across fix(release): install verified cargo-binstall binary directly #5203/fix(release): install verified cargo-binstall binary directly #5204/fix(release): install verified cargo-binstall binary directly #5205. The architecture-selected official archive passed its embedded SHA-256 check; extraction/direct installation succeeded; the exact finalcargo binstall -V | grep -Fx "${BINSTALL_VERSION}"returned 1.10.11, exit 0.sha256:2ef7934f6877b4b78bdc3d4b81c07ee260d1648c0338c86145cec02760390a24, nonroot UID/GID 1001, 1 CPU, 512 MiB, 64 PIDs, read-only root, temporary writable filesystems, drop-all capabilities and no-new-privileges. No CI token, secret mount, Docker socket, device or persistent volume was supplied. The container is absent afterward; no volumes were created. The ordinary worker's ID/image/start time/resource limits/restart count are unchanged.PR Hygiene ·
63455a2/self-reviewedDockerfile) — QuantumExplorer or shumkovWhen every box is checked the
PR Hygienecheck passes and this can merge.