Skip to content

fix(release): install verified cargo-binstall binary directly - #5205

Open
ktechmidas wants to merge 1 commit into
v6.0-devfrom
ci/binstall-direct-verified-v5-20260929
Open

ktechmidas wants to merge 1 commit into
v6.0-devfrom
ci/binstall-direct-verified-v5-20260929

Conversation

@ktechmidas

@ktechmidas ktechmidas commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Issue being fixed or feature implemented

Same release bootstrap defect as #5203: cargo-binstall1.10.11 downloaded a prebuilt binary, then redundantly reinstalled itself; a GitHub timeout caused an unlocked, incompatible source fallback.

What was done?

Propagate the identical, checksum-verified direct install to v5.0-dev. The source Dockerfile was byte-for-byte identical to v4.2 (blob6984e3ad); the repaired Dockerfile is also identical (blob147093ca). One file only, no application history or contributor branch changes.

  • Directly install the verified1.10.11 archive binary for AMD64/ARM64.
  • Pin both archive SHA256 values; bounded HTTPS retries and installed-version check.
  • Preserve the tool version and downstream locked installations.

How Has This Been Tested?

Both official archives downloaded and checksum/member checks passed. Exact repaired installation block executed in an isolated2CPU/2GiB AMD64 container with real Cargo: version1.10.11 verified. Reused that evidence because source and result blobs are identical across all three branches. Shell syntax and diff checks pass. ARM64 binary execution/full application image builds are not claimed complete; normal hosted CI/review remains required.

Breaking Changes

None. Removes the unintended self-compilation path. Existing release tags are unchanged and no workflow rerun/publication is requested.

Checklist

  • One-file change; identical patch validated against this branch
  • Real AMD64 installation proof, both archive checksums pinned
  • Hosted checks and independent reviews complete

Prepared by infraclaw with the authorized internal-branch/PAT route; account attribution is not a personal approval.

Additional native ARM64 validation — 2026-09-29 16:37 UTC

infraclaw verification update (not a personal review/approval by the protected transport account):

  • Native Linux aarch64 execution now passed, not QEMU and not an archive-only check. The unchanged cargo-binstall RUN body was extracted from Dockerfile blob 147093ca4bcc3df5e77d0e47501548444cc63711, which is identical across fix(release): install verified cargo-binstall binary directly #5203/fix(release): install verified cargo-binstall binary directly #5204/fix(release): install verified cargo-binstall binary directly #5205. The architecture-selected official archive passed its embedded SHA-256 check; extraction/direct installation succeeded; the exact final cargo binstall -V | grep -Fx "${BINSTALL_VERSION}" returned 1.10.11, exit 0.
  • The temporary, unregistered container used existing immutable ARM64 image sha256:2ef7934f6877b4b78bdc3d4b81c07ee260d1648c0338c86145cec02760390a24, nonroot UID/GID 1001, 1 CPU, 512 MiB, 64 PIDs, read-only root, temporary writable filesystems, drop-all capabilities and no-new-privileges. No CI token, secret mount, Docker socket, device or persistent volume was supplied. The container is absent afterward; no volumes were created. The ordinary worker's ID/image/start time/resource limits/restart count are unchanged.
  • The first synthetic harness attempt used UID 0 with all capabilities dropped and could not access the image's user-owned Cargo path; its downloaded archive verified and it cleaned up. Only the disposable harness was corrected to the image's intended nonroot identity. No Dockerfile, runner or workflow was changed for the passing proof.
  • Together with the previous AMD64 install check, this covers native installation/version checks on both architectures. It is not a full multi-stage Platform image build, application/test result, or replacement for the normal independent review/PR Hygiene gates. The PR's normal Docker jobs were skipped; that limitation remains explicit. No release retry, retag or publication was performed.

PR Hygiene · 8a8ac2c

  • Bots — coderabbitai skipped after the window · thepastaclaw ✓
  • Self-review — post /self-reviewed
  • Within your 5 open PRs — this one is beyond the limit; it waits until one merges
  • Build green
  • Approvals
    • files with no dedicated owner (Dockerfile) — QuantumExplorer or shumkov

When every box is checked the PR Hygiene check passes and this can merge.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: dashpay/platform/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: eddc34a3-57a8-4fdf-bcb8-fde2662a2d6d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added this to the v5.0.0 milestone Sep 29, 2026
@github-actions github-actions Bot added the waiting-bots Waiting for the review bots to report on this head label Sep 29, 2026
@thepastaclaw

thepastaclaw commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

✅ Final review complete — no blockers (commit 8a8ac2c) · triage: low · Phase 2 only (queue backlog)

@thepastaclaw thepastaclaw left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Final validation — Phase 2 only (queue backlog)

Verified the exact-head, one-file Dockerfile change against the supplied Phase-2 reviews; no actionable in-scope defects were found. The installation checks the architecture-specific archive checksum before extraction, installs directly into the inherited Cargo directory, verifies the installed version, and preserves downstream locked installations. Shell syntax and diff checks passed locally; release-archive checks, native execution, and full image builds were not independently repeated during this verification.

Review provenance

Source: reviewer 1: gpt-6-astra (agent: phase2-reviewer, role: general); reviewer 2: gpt-6-astra (agent: phase2-reviewer, role: architecture-layering); final verifier: gpt-6-astra (agent: astra-verifier, role: final-verifier)

  • Triage: low by gpt-6-astra (effort low) — This is a small, self-contained Dockerfile installation fix that changes build tooling behavior but does not affect application logic or any critical surface.
  • Phase 1 reviewers: not run (skipped for throughput: 13 PRs queued, above the 10 limit)
  • Fresh verifier: gpt-6-astra — final-verifier; agent astra-verifier
  • Phase 2 reviewers: gpt-6-astra — general (completed, effort medium); agent phase2-reviewer, gpt-6-astra — architecture-layering (completed, effort medium); agent phase2-reviewer

@github-actions github-actions Bot removed the waiting-bots Waiting for the review bots to report on this head label Sep 30, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bots are done — your move: post /self-reviewed.
Full checklist in the description.

@github-actions github-actions Bot added waiting-self-review Waiting for the author to post /self-reviewed bot-review-skipped A required review bot did not report; it was skipped by the window or by a person. labels Oct 2, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot-review-skipped A required review bot did not report; it was skipped by the window or by a person. waiting-self-review Waiting for the author to post /self-reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants