Skip to content

fix(release): install verified cargo-binstall binary directly - #5204

Open
ktechmidas wants to merge 1 commit into
v5.1-devfrom
ci/binstall-direct-verified-v43-20260929
Open

ktechmidas wants to merge 1 commit into
v5.1-devfrom
ci/binstall-direct-verified-v43-20260929

Conversation

@ktechmidas

@ktechmidas ktechmidas commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Issue being fixed or feature implemented

Same release bootstrap defect as #5203: cargo-binstall1.10.11 downloaded a prebuilt binary, then redundantly reinstalled itself; a GitHub timeout caused an unlocked, incompatible source fallback.

What was done?

Propagate the identical, checksum-verified direct install to v4.3-dev. The source Dockerfile was byte-for-byte identical to v4.2 (blob6984e3ad); the repaired Dockerfile is also identical (blob147093ca). One file only, no application history or contributor branch changes.

  • Directly install the verified1.10.11 archive binary for AMD64/ARM64.
  • Pin both archive SHA256 values; bounded HTTPS retries and installed-version check.
  • Preserve the tool version and downstream locked installations.

How Has This Been Tested?

Both official archives downloaded and checksum/member checks passed. Exact repaired installation block executed in an isolated2CPU/2GiB AMD64 container with real Cargo: version1.10.11 verified. Reused that evidence because source and result blobs are identical across all three branches. Shell syntax and diff checks pass. ARM64 binary execution/full application image builds are not claimed complete; normal hosted CI/review remains required.

Breaking Changes

None. Removes the unintended self-compilation path. Existing release tags are unchanged and no workflow rerun/publication is requested.

Checklist

  • One-file change; identical patch validated against this branch
  • Real AMD64 installation proof, both archive checksums pinned
  • Hosted checks and independent reviews complete

Prepared by infraclaw with the authorized internal-branch/PAT route; account attribution is not a personal approval.

Additional native ARM64 validation — 2026-09-29 16:37 UTC

infraclaw verification update (not a personal review/approval by the protected transport account):

  • Native Linux aarch64 execution now passed, not QEMU and not an archive-only check. The unchanged cargo-binstall RUN body was extracted from Dockerfile blob 147093ca4bcc3df5e77d0e47501548444cc63711, which is identical across fix(release): install verified cargo-binstall binary directly #5203/fix(release): install verified cargo-binstall binary directly #5204/fix(release): install verified cargo-binstall binary directly #5205. The architecture-selected official archive passed its embedded SHA-256 check; extraction/direct installation succeeded; the exact final cargo binstall -V | grep -Fx "${BINSTALL_VERSION}" returned 1.10.11, exit 0.
  • The temporary, unregistered container used existing immutable ARM64 image sha256:2ef7934f6877b4b78bdc3d4b81c07ee260d1648c0338c86145cec02760390a24, nonroot UID/GID 1001, 1 CPU, 512 MiB, 64 PIDs, read-only root, temporary writable filesystems, drop-all capabilities and no-new-privileges. No CI token, secret mount, Docker socket, device or persistent volume was supplied. The container is absent afterward; no volumes were created. The ordinary worker's ID/image/start time/resource limits/restart count are unchanged.
  • The first synthetic harness attempt used UID 0 with all capabilities dropped and could not access the image's user-owned Cargo path; its downloaded archive verified and it cleaned up. Only the disposable harness was corrected to the image's intended nonroot identity. No Dockerfile, runner or workflow was changed for the passing proof.
  • Together with the previous AMD64 install check, this covers native installation/version checks on both architectures. It is not a full multi-stage Platform image build, application/test result, or replacement for the normal independent review/PR Hygiene gates. The PR's normal Docker jobs were skipped; that limitation remains explicit. No release retry, retag or publication was performed.

PR Hygiene · 63455a2

  • Bots — coderabbitai skipped after the window · thepastaclaw ✓
  • Self-review — post /self-reviewed
  • Within your 5 open PRs — this one is beyond the limit; it waits until one merges
  • Build green
  • Approvals
    • files with no dedicated owner (Dockerfile) — QuantumExplorer or shumkov

When every box is checked the PR Hygiene check passes and this can merge.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: dashpay/platform/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: bb0fe7d4-e1a8-4e22-bbdb-3cf6a2fc9e27

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added this to the v4.3.0 milestone Sep 29, 2026
@github-actions github-actions Bot added the waiting-bots Waiting for the review bots to report on this head label Sep 29, 2026
@thepastaclaw

thepastaclaw commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

⚠️ DEGRADED — Final review complete — no blockers (commit 63455a2) · triage: low · Phase 2 only (queue backlog) · stand-in models (primary models out of quota)

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ DEGRADED — Final validation — Phase 2 only (queue backlog)

⚠️ DEGRADED review. The primary review models were unavailable (gpt-6-astra unavailable: Request rejected (429) · All credentials for model gpt-6-astra are cooling down (last error: usage_limit_reached: The us), so this review ran on stand-in models: gpt-5.6-luna → muse-spark-1.3-contributor, gpt-5.6-sol → muse-spark-1.3-contributor, gpt-5.6-terra → muse-spark-1.3-contributor, gpt-6-astra → muse-spark-1.3-contributor. Both review phases and the independent verifiers still ran, but on weaker models, with Phase 1 capped at high effort. Treat the verdict as provisional; a full-strength re-review will run on the next push once the primary models are back.

Dockerfile-only bootstrap fix replaces the redundant cargo-binstall self-reinstall with a checksum-verified direct binary install for both amd64 and arm64. SHA pinning, bounded HTTPS retries, and the trailing version gate are all correct, with no protocol, storage, or dependency-boundary impact.

Review provenance

Source: reviewer 1: muse-spark-1.3-contributor (standing in for gpt-6-astra) (agent: phase2-reviewer, role: general); reviewer 2: muse-spark-1.3-contributor (standing in for gpt-6-astra) (agent: phase2-reviewer, role: architecture-layering); final verifier: muse-spark-1.3-contributor (standing in for gpt-6-astra) (agent: astra-verifier, role: final-verifier)

  • Degraded mode: gpt-6-astra unavailable: Request rejected (429) · All credentials for model gpt-6-astra are cooling down (last error: usage_limit_reached: The us (detected by probe, since 2026-09-29T17:13:01Z); stand-ins gpt-5.6-luna → muse-spark-1.3-contributor, gpt-5.6-sol → muse-spark-1.3-contributor, gpt-5.6-terra → muse-spark-1.3-contributor, gpt-6-astra → muse-spark-1.3-contributor; Phase 1 effort capped at high
  • Triage: low by muse-spark-1.3-contributor (standing in for gpt-6-astra) (effort low) — One-file Dockerfile-only build fix pinning the verified binary with no application logic change.
  • Phase 1 reviewers: not run (skipped for throughput: 11 PRs queued, above the 10 limit)
  • Fresh verifier: muse-spark-1.3-contributor (standing in for gpt-6-astra) — final-verifier; agent astra-verifier
  • Phase 2 reviewers: muse-spark-1.3-contributor (standing in for gpt-6-astra) — general (completed, effort medium); agent phase2-reviewer, muse-spark-1.3-contributor (standing in for gpt-6-astra) — architecture-layering (completed, effort medium); agent phase2-reviewer

@github-actions github-actions Bot removed the waiting-bots Waiting for the review bots to report on this head label Sep 30, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bots are done — your move: post /self-reviewed.
Full checklist in the description.

@github-actions github-actions Bot added waiting-self-review Waiting for the author to post /self-reviewed bot-review-skipped A required review bot did not report; it was skipped by the window or by a person. labels Oct 2, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot-review-skipped A required review bot did not report; it was skipped by the window or by a person. waiting-self-review Waiting for the author to post /self-reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants