Skip to content

Feat/provisioning check reusable signed - #1130

Merged
hyperpolymath merged 3 commits into
mainfrom
feat/provisioning-check-reusable-signed
Oct 2, 2026
Merged

hyperpolymath merged 3 commits into
mainfrom
feat/provisioning-check-reusable-signed

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

hyperpolymath and others added 2 commits October 1, 2026 15:50
Re-signed rebuild of #1096 (head 18dcefa) on current main. Two coderabbitai[bot]
commits on that branch were unsigned, which required_signatures refuses even under
squash. The tree equals 18dcefa apart from main's later #1087/#1098 files, plus:

- hypatia:ignore eval_in_shell pragmas on 7 lines of provision-check.sh and
  provision-lib.sh. Each hit is the word "eval" (a verb name or the .eval/
  directory), never the shell builtin. Inline pragmas, not baseline entries:
  the templates are minted into other repos, where the pragma travels with them.
  Control: hypatia@4065424 reports 7 findings before and 0 after.

Original commits (feat/provisioning-canon):
  fd0658c feat(provisioning): estate provisioning standard + launcher v0.5 modes
  e7b134e fix(provisioning): detect ABI/FFI layout; launcher is generated
  40010ef fix(provisioning): no curl|sh install hint; regenerate registry
  206eb6c feat(provisioning): one placement resolver; zig found 3 dirs down
  39b790f fix(provisioning): no faked zig/bun tests; one ai-install sentence
  eaf3a89 feat(provisioning): fmt-check verb, the check-only twin of fmt
  b234caf fix(provisioning): #1096 review — hook isolation, dispatch rc, quoting
  89c1d32 fix(provisioning): one set of predicates for doctor and the CI gate
  93342bf docs(provisioning): banned-tool mise.toml is replaced; app launchers
  7e6f3db feat(provisioning): toolchain-refresh regenerates build/guix/crates.scm
  9b57453 fix(provisioning): mise.lock checksums are checked per platform table
  7475b18 docs(provisioning): document the awk helper in mise_lock_gaps
  e323e0a docs(provisioning): escape the [[ai-install]] anchor in prose
  42b66c3 fix(provisioning): guix-only re-pin, tally-last doctor, artefact kinds
  b01a245 fix(provisioning): PV-W23 reads every mise config and backend
  bf7c97a fix(provisioning): a bare mise name with only npm backends is banned
  a00fcf3 Update 3-practice/provisioning/templates/launcher.sh.tmpl
  71cad01 docs(provisioning): document shell template functions
  18dcefa docs(provisioning): clarify template function behavior and exit statuses

Co-Authored-By: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DAKujx2PXHcVSA7vncTNH1
provisioning-check-reusable.yml checks a caller against the provisioning
canon at the workflow's own commit (job.workflow_sha), in two steps that
report separately:

- engine drift: build/just/{provision.just,provision-lib.sh,
  provision-modes.sh,provision-check.sh} must be byte-identical to the
  canon. channels.scm is not compared: toolchain-refresh re-pins it per
  repo, and provision-check.sh checks the pin instead.
- conformance: the canon provision-check.sh (not the caller's copy) runs
  against the caller without --dev, so template residue fails.

just 1.56.0 is installed from the release tarball pinned by sha256; no
new action is used. actions.lock gains the section by hand (the lock's
membership check is global, so a missing section would go unnoticed),
and canon.lock lists the reusable under [canon.workflows].

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UkSmyapDUmuGyyZSJmvbKy
(cherry picked from commit 96d5828)
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 59 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c268add7-e6de-44aa-aed7-760c95dda564

📥 Commits

Reviewing files that changed from the base of the PR and between 11ba299 and a91cb91.

⛔ Files ignored due to path filters (2)
  • .github/workflows/actions.lock is excluded by !**/*.lock
  • canon.lock is excluded by !**/*.lock
📒 Files selected for processing (25)
  • .github/workflows/provisioning-check-reusable.yml
  • 3-practice/provisioning/PROVISIONING-STANDARD.adoc
  • 3-practice/provisioning/provisioning-standard_praxis.deed
  • 3-practice/provisioning/templates/.machine_readable/descriptiles/provisioning_praxis.deed.tmpl
  • 3-practice/provisioning/templates/Justfile.tmpl
  • 3-practice/provisioning/templates/README-ai-install.adoc.tmpl
  • 3-practice/provisioning/templates/build/just/provision-check.sh
  • 3-practice/provisioning/templates/build/just/provision-lib.sh
  • 3-practice/provisioning/templates/build/just/provision-modes.sh
  • 3-practice/provisioning/templates/build/just/provision.just
  • 3-practice/provisioning/templates/docs/AI_INSTALLATION_GUIDE.adoc.tmpl
  • 3-practice/provisioning/templates/docs/SETUP.adoc.tmpl
  • 3-practice/provisioning/templates/guix/channels.scm
  • 3-practice/provisioning/templates/guix/guix.scm.cargo.tmpl
  • 3-practice/provisioning/templates/guix/guix.scm.source.tmpl
  • 3-practice/provisioning/templates/guix/manifest.scm.tmpl
  • 3-practice/provisioning/templates/launcher.sh.tmpl
  • 3-practice/provisioning/templates/llm-warmup-dev.adoc.tmpl
  • 3-practice/provisioning/templates/llm-warmup-maintainer.adoc.tmpl
  • 3-practice/provisioning/templates/llm-warmup-user.adoc.tmpl
  • 3-practice/provisioning/templates/mise.toml.tmpl
  • docs/UX-standards/launcher-standard.adoc
  • guix.scm
  • launcher/launcher-standard_praxis.deed
  • scripts/check-launcher-standard-currency.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@hyperpolymath
hyperpolymath merged commit 202a215 into main Oct 2, 2026
50 checks passed
@hyperpolymath
hyperpolymath deleted the feat/provisioning-check-reusable-signed branch October 2, 2026 01:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant