Install the focused guard test runner from wheels only - #136
Conversation
Reviewer's GuideThe focused guard workflow now installs pytest 8.3.4 with pip restricted to wheels, preventing source-package build scripts while leaving guard behavior, command bytes, and the canonical verification suite unchanged; accompanying spec artifacts document the correction and validation. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The unquoted :all: argument makes the workflow invalid YAML, preventing CI from running.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Hardens the focused guard CI job by requiring wheel-only pytest installation.
Changes:
- Adds
--only-binary=:all:to the pinned pytest install. - Documents the security correction and verification plan.
| File | Description |
|---|---|
.github/workflows/tests.yml |
Enforces wheel-only installation. |
specs/003-binary-only-guard-runner/spec.md |
Defines the requirement. |
specs/003-binary-only-guard-runner/plan.md |
Records the implementation plan. |
specs/003-binary-only-guard-runner/tasks.md |
Records completion and verification. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Bring in #81 (lane-rename and the lane alias table), #129, #131, #133, #135 and #136 so the PR is mergeable again. Two textual conflicts, both resolved so each side's intent survives: - lanes-edit.sh, the `*)` arm's unknown-subcommand list: main added `rename-lane`, this branch added `duplicate-holder`. The list now carries both, which is what test_repo_hygiene's derived-list check demands of the dispatcher. - tests/test_lane_helpers.sh, the suite's fakebin: main added a fake `gh` (Copilot round 7 on #81), this branch added fake `pgrep` and `ps` (issue #39). All three fakes are kept and the one chmod line marks all five fakebin entries executable. No new main code calls pgrep or ps, so the suite-wide fakes change nothing for main's new cases; and main's file-keyed LOG_AWK lane field leaves holder_is_dead's verb-only read and superseded_by's tolower comparison unchanged in meaning. Lane: openRepoTools-3 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…#131 #133 #135 #136): one cap conflict, settled at the count of what merged One textual conflict, the AGENTS.md line cap in tests/test_repo_hygiene.py: this branch raised 265 to 278 for Amendment 18's ONE BINDING rule, and #119 raised the same 265 to 292 for the cycle's three rulings. AGENTS.md itself auto-merged to 305 lines, 265 + 13 + 27, with both paragraphs whole and #135's profile-only guard sentence beside them. So the cap is 305, with a dated MEET AT entry in the form the 224 entry's rule asks for, rather than either side's number. Everything else auto-merged and was read for meaning, not just for markers. #135 hoists the global-flag parse in lanes-edit.sh above the path probes and exits 0 for `guard` under exact CLAUDE_NO_LANE=1; this branch's guard clauses (d) and (e) sit inside the guard, after that exit, which is right because a profile-only session holds no binding. Every positional read between the new and old parse sites is inside a function. #129's lclaude-first launcher in `lane` is the one this branch's elsewhere and available paths already call. #133's stable_lane_row and #129's lclaude fakes are cases of their own and touch none of this branch's. Lane: openRepoTools-3 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bring #97 onto a current base before the seam rework Brett Heap ruled on 2026-10-04 ("managed ledger owns enrolled lanes; #97 owns legacy — rework both"). Main moved 14 commits past 957a26f, to daed209: #81 lane-rename, #83 Amendment 18, #93 Amendment 19, #61 claim --force takeover, #146, #119, #101-#103, #129, #131, #133, #135, #136, #139 and #134. Four files conflicted, and in every one both intents survive: - lanes-edit.sh, the function sections: both sides appended after migrate_state_cells. Main's Amendment 19(c)/(d) sweep and archive stay directly under it, because its header says "the shape `migrate-state-cells` has one screen up"; #97's lifecycle and inventory section follows them. - lanes-edit.sh, the unknown-subcommand refusal: the union of both lists, 56 names, the same set as the dispatcher's 56 arms. - lanes-edit.sh, the exit-code table, and the manual's copy of it: #97's 7 row ("another act got there first", in three verbs) is kept, and exit 9 now has two meanings, one per verb. #61 spent 9 on `claim --force`'s abandoned takeover and #97 spent it on `lane-state`'s unreadable snapshot, and each PR took it as unused. Neither verb can return the other's 9, so the table names both and nothing is renumbered in a merge. The manual's 9 row said "(`claim` only)", which the merge would have made false; its 7 row now names #97's two fenced writers too, as the code table already did. The next commit moves #97's 9 to 10. - lane-handoff, the late-record restart line: #129's `$lane_profile_word` (lclaude) with #97's lifecycle line under it. - docs/README-lanes.md: Amendment 19's section, then #97's #91 section, so the amendment sections stay in number order. - tests/test_lane_helpers.sh: main's Amendment 19 and Amendment 18 sections run first, in main's order (A18's restores its fixtures), and #97's self-contained #91 section follows them, before the workstation-seam section, as it did on #97's branch. lane-start auto-merged around #134's rewrite. #97's section 4a still prints the reconciliation after Amendment 18's binding gate and before section 5 and the STARTED/RESUMED write in 5b. AGENTS.md, README.md, tests/test_repo_hygiene.py and skills/ are byte-identical to main, so the 316- and 486-line caps already match the merged counts. Locally, tests/run.sh -k 'lane_helpers_suite or repo_hygiene or lane_start_claude_current or guard_launch_mode or install_skill_and_hook': 274 passed, 600 deselected, in 1560 s. Lane: openRepoTools-3 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>




Summary
Follow up on openRepoTools#135's late Sonar annotation: install the focused
guard test runner using
--only-binary=:all:so pip cannot execute sourcepackage build scripts. Preserve the pinned pytest version and canonical wrapper.
Runtime guard behavior and vendored command bytes are unchanged.
Implementation:
specs/003-binary-only-guard-runner/.CI reruns the focused guard and hygiene checks and Sonar analysis.
This session is outside a lane under brettheap/new-workstation#47.
Summary by Sourcery
Install the focused guard test runner from wheels only while preserving its pinned version and existing runtime behavior.
Bug Fixes:
CI:
Chores: