From 6ba6befe4ca6a9f0ba1a99acdd5f62b6dbdec2ab Mon Sep 17 00:00:00 2001 From: Brett Heap <1513478+brettheap@users.noreply.github.com> Date: Wed, 30 Sep 2026 18:46:47 +0000 Subject: [PATCH 1/2] ci: install the focused guard test runner from wheels only --- .github/workflows/tests.yml | 2 +- specs/003-binary-only-guard-runner/plan.md | 6 ++++++ specs/003-binary-only-guard-runner/spec.md | 6 ++++++ specs/003-binary-only-guard-runner/tasks.md | 8 ++++++++ 4 files changed, 21 insertions(+), 1 deletion(-) create mode 100644 specs/003-binary-only-guard-runner/plan.md create mode 100644 specs/003-binary-only-guard-runner/spec.md create mode 100644 specs/003-binary-only-guard-runner/tasks.md diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 161c292..e7fadde 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -38,7 +38,7 @@ jobs: with: python-version: '3.x' - name: install the test runner - run: python3 -m pip install --disable-pip-version-check pytest==8.3.4 + run: python3 -m pip install --disable-pip-version-check --only-binary=:all: pytest==8.3.4 - name: guard launch mode and repository hygiene env: GIT_AUTHOR_NAME: openRepoTools CI diff --git a/specs/003-binary-only-guard-runner/plan.md b/specs/003-binary-only-guard-runner/plan.md new file mode 100644 index 0000000..7064e6a --- /dev/null +++ b/specs/003-binary-only-guard-runner/plan.md @@ -0,0 +1,6 @@ +# Plan + +Add pip's `--only-binary=:all:` flag to the focused guard job, preserving the +pinned runner version and canonical test wrapper. Validate through that focused +CI job and Sonar analysis. This is an implementation correction within the +existing guard change, so it adds no separate OpenSpec governance proposal. diff --git a/specs/003-binary-only-guard-runner/spec.md b/specs/003-binary-only-guard-runner/spec.md new file mode 100644 index 0000000..80b87e7 --- /dev/null +++ b/specs/003-binary-only-guard-runner/spec.md @@ -0,0 +1,6 @@ +# Feature: Install the focused guard test runner from wheels + +Follow-up to feature `002-skip-no-lane-guard` and PR #135. A late Sonar review +flagged the new focused job's ability to execute package source build scripts. +Require binary distributions for its pinned pytest installation. Runtime guard +behavior and vendored command bytes do not change. diff --git a/specs/003-binary-only-guard-runner/tasks.md b/specs/003-binary-only-guard-runner/tasks.md new file mode 100644 index 0000000..c999c81 --- /dev/null +++ b/specs/003-binary-only-guard-runner/tasks.md @@ -0,0 +1,8 @@ +# Tasks + +- [x] T001 Restrict the focused test-runner installation to binary distributions. + +## Verification + +The diff changes the new focused job's install command only. CI verifies the +wheel installation and reruns the same canonical 165-check guard/hygiene suite. From 42860a93be192f025a725708d7a016083ff82923 Mon Sep 17 00:00:00 2001 From: Brett Heap <1513478+brettheap@users.noreply.github.com> Date: Wed, 30 Sep 2026 18:51:04 +0000 Subject: [PATCH 2/2] ci: quote the wheel-only pip command as a YAML scalar --- .github/workflows/tests.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index e7fadde..7f23afb 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -38,7 +38,7 @@ jobs: with: python-version: '3.x' - name: install the test runner - run: python3 -m pip install --disable-pip-version-check --only-binary=:all: pytest==8.3.4 + run: 'python3 -m pip install --disable-pip-version-check --only-binary=:all: pytest==8.3.4' - name: guard launch mode and repository hygiene env: GIT_AUTHOR_NAME: openRepoTools CI