Skip to content

Install the focused guard test runner from wheels only - #136

Merged
brettheap merged 2 commits into
mainfrom
003-binary-only-guard-runner
Sep 30, 2026
Merged

brettheap merged 2 commits into
mainfrom
003-binary-only-guard-runner

Conversation

@brettheap

@brettheap brettheap commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Follow up on openRepoTools#135's late Sonar annotation: install the focused
guard test runner using --only-binary=:all: so pip cannot execute source
package build scripts. Preserve the pinned pytest version and canonical wrapper.

Runtime guard behavior and vendored command bytes are unchanged.
Implementation: specs/003-binary-only-guard-runner/.

CI reruns the focused guard and hygiene checks and Sonar analysis.
This session is outside a lane under brettheap/new-workstation#47.

Summary by Sourcery

Install the focused guard test runner from wheels only while preserving its pinned version and existing runtime behavior.

Bug Fixes:

  • Require the focused guard job to install its pinned pytest runner from binary distributions only, preventing source package build scripts from executing.

CI:

  • Document validation of the wheel-only runner installation through the focused guard and hygiene checks.

Chores:

  • Add implementation specification and task tracking for the binary-only guard runner change.

Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:47
@sourcery-ai

sourcery-ai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

The focused guard workflow now installs pytest 8.3.4 with pip restricted to wheels, preventing source-package build scripts while leaving guard behavior, command bytes, and the canonical verification suite unchanged; accompanying spec artifacts document the correction and validation.

File-Level Changes

Change Details Files
Require the focused CI job to install its pinned pytest runner exclusively from binary distributions.
  • Add pip's --only-binary=:all: option while preserving the existing pytest version and other install settings.
  • Document the follow-up specification, implementation plan, completed task, and verification scope.
.github/workflows/tests.yml
specs/003-binary-only-guard-runner/plan.md
specs/003-binary-only-guard-runner/spec.md
specs/003-binary-only-guard-runner/tasks.md

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

sourcery-ai[bot]
sourcery-ai Bot previously approved these changes Sep 30, 2026

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Approved.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@brettheap

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The unquoted :all: argument makes the workflow invalid YAML, preventing CI from running.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Hardens the focused guard CI job by requiring wheel-only pytest installation.

Changes:

  • Adds --only-binary=:all: to the pinned pytest install.
  • Documents the security correction and verification plan.
File Description
.github/​workflows/​tests.yml Enforces wheel-only installation.
specs/​003-binary-only-guard-runner/​spec.md Defines the requirement.
specs/​003-binary-only-guard-runner/​plan.md Records the implementation plan.
specs/​003-binary-only-guard-runner/​tasks.md Records completion and verification.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/tests.yml Outdated
Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:51
@sonarqubecloud

Copy link
Copy Markdown

@brettheap

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The focused security hardening is correct, scoped as described, and preserves the pinned runner and canonical test wrapper.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@brettheap
brettheap merged commit cbb5981 into main Sep 30, 2026
8 checks passed
brettheap added a commit that referenced this pull request Oct 2, 2026
Brings #135 (skip the lane name guard for profile-only launches) and #136
(the focused guard test runner from wheels only) onto the branch. The merge
is clean; nothing of either is resolved by hand.

Lane: openRepoTools-3
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
brettheap added a commit that referenced this pull request Oct 3, 2026
Bring in #81 (lane-rename and the lane alias table), #129, #131, #133,
#135 and #136 so the PR is mergeable again. Two textual conflicts, both
resolved so each side's intent survives:

- lanes-edit.sh, the `*)` arm's unknown-subcommand list: main added
  `rename-lane`, this branch added `duplicate-holder`. The list now
  carries both, which is what test_repo_hygiene's derived-list check
  demands of the dispatcher.
- tests/test_lane_helpers.sh, the suite's fakebin: main added a fake
  `gh` (Copilot round 7 on #81), this branch added fake `pgrep` and
  `ps` (issue #39). All three fakes are kept and the one chmod line
  marks all five fakebin entries executable.

No new main code calls pgrep or ps, so the suite-wide fakes change
nothing for main's new cases; and main's file-keyed LOG_AWK lane field
leaves holder_is_dead's verb-only read and superseded_by's tolower
comparison unchanged in meaning.

Lane: openRepoTools-3
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
brettheap added a commit that referenced this pull request Oct 3, 2026
…#131 #133 #135 #136): one cap conflict, settled at the count of what merged

One textual conflict, the AGENTS.md line cap in
tests/test_repo_hygiene.py: this branch raised 265 to 278 for Amendment
18's ONE BINDING rule, and #119 raised the same 265 to 292 for the
cycle's three rulings. AGENTS.md itself auto-merged to 305 lines,
265 + 13 + 27, with both paragraphs whole and #135's profile-only guard
sentence beside them. So the cap is 305, with a dated MEET AT entry in
the form the 224 entry's rule asks for, rather than either side's
number.

Everything else auto-merged and was read for meaning, not just for
markers. #135 hoists the global-flag parse in lanes-edit.sh above the
path probes and exits 0 for `guard` under exact CLAUDE_NO_LANE=1; this
branch's guard clauses (d) and (e) sit inside the guard, after that
exit, which is right because a profile-only session holds no binding.
Every positional read between the new and old parse sites is inside a
function. #129's lclaude-first launcher in `lane` is the one this
branch's elsewhere and available paths already call. #133's
stable_lane_row and #129's lclaude fakes are cases of their own and
touch none of this branch's.

Lane: openRepoTools-3
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@brettheap
brettheap deleted the 003-binary-only-guard-runner branch October 3, 2026 18:49
brettheap added a commit that referenced this pull request Oct 4, 2026
Bring #97 onto a current base before the seam rework Brett Heap ruled on
2026-10-04 ("managed ledger owns enrolled lanes; #97 owns legacy — rework
both"). Main moved 14 commits past 957a26f, to daed209: #81 lane-rename,
#83 Amendment 18, #93 Amendment 19, #61 claim --force takeover, #146,
#119, #101-#103, #129, #131, #133, #135, #136, #139 and #134.

Four files conflicted, and in every one both intents survive:

- lanes-edit.sh, the function sections: both sides appended after
  migrate_state_cells. Main's Amendment 19(c)/(d) sweep and archive stay
  directly under it, because its header says "the shape
  `migrate-state-cells` has one screen up"; #97's lifecycle and
  inventory section follows them.
- lanes-edit.sh, the unknown-subcommand refusal: the union of both lists,
  56 names, the same set as the dispatcher's 56 arms.
- lanes-edit.sh, the exit-code table, and the manual's copy of it: #97's
  7 row ("another act got there first", in three verbs) is kept, and exit
  9 now has two meanings, one per verb. #61 spent 9 on `claim --force`'s
  abandoned takeover and #97 spent it on `lane-state`'s unreadable
  snapshot, and each PR took it as unused. Neither verb can return the
  other's 9, so the table names both and nothing is renumbered in a
  merge. The manual's 9 row said "(`claim` only)", which the merge would
  have made false; its 7 row now names #97's two fenced writers too, as
  the code table already did. The next commit moves #97's 9 to 10.
- lane-handoff, the late-record restart line: #129's
  `$lane_profile_word` (lclaude) with #97's lifecycle line under it.
- docs/README-lanes.md: Amendment 19's section, then #97's #91 section,
  so the amendment sections stay in number order.
- tests/test_lane_helpers.sh: main's Amendment 19 and Amendment 18
  sections run first, in main's order (A18's restores its fixtures), and
  #97's self-contained #91 section follows them, before the
  workstation-seam section, as it did on #97's branch.

lane-start auto-merged around #134's rewrite. #97's section 4a still
prints the reconciliation after Amendment 18's binding gate and before
section 5 and the STARTED/RESUMED write in 5b. AGENTS.md, README.md,
tests/test_repo_hygiene.py and skills/ are byte-identical to main, so
the 316- and 486-line caps already match the merged counts.

Locally, tests/run.sh -k 'lane_helpers_suite or repo_hygiene or
lane_start_claude_current or guard_launch_mode or install_skill_and_hook':
274 passed, 600 deselected, in 1560 s.

Lane: openRepoTools-3
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants