Skip to content

feat(ansible): install sentrux so the structural gate runs on fleet hosts - #33

Merged
undeemed merged 1 commit into
mainfrom
fm/cf-sentrux-install-x1
Oct 2, 2026
Merged

undeemed merged 1 commit into
mainfrom
fm/cf-sentrux-install-x1

Conversation

@undeemed

@undeemed undeemed commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Intent

once all is done, sync setup to code factory

Context: that is the standing order that the fleet host's generic setup is reproduced by Code-Factory on every run, latest versions, never pinned, downloads verified by published checksums. The fleet's standing rule is that every session runs the Sentrux structural gate (sentrux gate ., whose line reads Quality: <baseline> -> <current>; a drop of more than 250 points against the repository's own baseline blocks), and the captain's machine conventions put a sentrux baseline on every new repo. On the new fleet host command -v sentrux is empty and Code-Factory installs no sentrux at all, so on 2026-10-01 a worker reported "sentrux exit n/a (no sentrux binary or config on this host/tree)" and the gate silently did not run.

What Changed

  • scripts/install_tools.py now installs the latest sentrux release, checked against the GitHub release-asset digest, and links the binary into ~/.local/bin. It also installs that same release's grammars-<platform>.tar.gz and links the grammars into ~/.sentrux/plugins/<language>/grammars/, so sentrux doesn't download them unverified on first run. Tools from the same repo now share one "latest release" lookup.
  • sentrux is added to factory_core_tools, the installer's default --tools, the tools.yml contract comment, the verify.yml expected-files list and the container smoke script. libgtk-3-0t64 is added to the base packages, because the sentrux release binary links GTK 3 even for CLI use.
  • docs/dependencies.md documents the sentrux install, the GTK package, and the updated GitHub API request bound (at most ten). tests/test_install_tools.py is updated to match.

Risk Assessment

✅ Low: The change is a small, well-bounded addition that follows the existing btop/uv install pattern with digest verification, and every source path I traced works. The only gap is a smoke check that never runs the installed sentrux.

Testing

I ran the installer against live GitHub into a disposable home. It installed the latest sentrux (0.5.7) and linked its verified grammars, and a repeat run changed nothing. The installed binary then saved a baseline in a throwaway repo, and sentrux gate . printed Quality: 3981 -&gt; 3981, exit 0. A tampered checksum aborted with a mismatch, exit 1, and installed nothing. tests/test_install_tools.py passes (57). The Ansible playbook wiring is untested, because ansible-playbook is not on PATH and tests/container-smoke.sh needs a Docker daemon this user cannot reach (permission denied on /var/run/docker.sock). The disposable homes and temp venv were removed.

  • Live validation: ✅ go - 4 of 5 scenarios driven live against the product
Scenario Result Live Evidence
Resolve latest sentrux and grammars from the same release, each with a published sha256 ✅ pass live --tools sentrux --resolve output: sentrux and sentrux-grammars both v0.5.7, with sha256 values
Install on a fresh home puts a sentrux binary on PATH location, links verified grammars, and a repeat run is idempotent ✅ pass live First run changed:true, second changed:false; ~/.local/bin/sentrux and ~/.sentrux/plugins/c/grammars/linux-x86_64.so are symlinks into the code-factory tool store; sentrux.log
Installed sentrux runs the structural gate and reports Quality: baseline -> current ✅ pass live sentrux gate --save . then sentrux gate . gave Quality: 3981 -&gt; 3981, 'No degradation detected', exit 0
Adversarial: a checksum mismatch aborts the install and installs nothing ✅ pass live Tampered sha256 gave 'checksum mismatch', exit 1, no ~/.local/bin created
Ansible apply on a clean host installs libgtk-3-0t64 and sentrux, and verify.yml confirms ~/.local/bin/sentrux ⏸️ untested no ansible-playbook and ansible are not on PATH. docker is installed but the daemon is unreachable (permission denied on /var/run/docker.sock), so tests/container-smoke.sh cannot build or run the…
Evidence: sentrux install and gate transcript
install_tools.py --tools sentrux (real GitHub, disposable home): installed sentrux 0.5.7 + grammars symlinked; 2nd run changed:false
sentrux gate --save . -> Quality: 3981 ; sentrux gate . -> "Quality: 3981 -> 3981 / No degradation detected" exit 0
tampered sha256 -> "checksum mismatch", exit 1, nothing installed
pytest tests/test_install_tools.py: 57 passed

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

⚠️ **Review** - 1 info
  • ℹ️ tests/container-smoke.sh:231 - The smoke script now resolves and installs sentrux, but never runs it. check_resolved_releases loops over herdr gh no-mistakes treehouse, and check_core_tools loops over node bun uv, so neither runs sentrux --version. The reported failure was a gate that silently did not run. A missing GTK library, a broken symlink, or a wrong release asset would pass the smoke and only show up when a worker runs sentrux gate. Smallest remedy: add sentrux to the check_resolved_releases loop, since it already compares the reported version with the resolved stamp.
✅ **Test** - passed

✅ No issues found.

  • Live validation: ✅ go - 4 of 5 scenarios driven live against the product
Scenario Result Live Evidence
Resolve latest sentrux and grammars from the same release, each with a published sha256 ✅ pass live --tools sentrux --resolve output: sentrux and sentrux-grammars both v0.5.7, with sha256 values
Install on a fresh home puts a sentrux binary on PATH location, links verified grammars, and a repeat run is idempotent ✅ pass live First run changed:true, second changed:false; ~/.local/bin/sentrux and ~/.sentrux/plugins/c/grammars/linux-x86_64.so are symlinks into the code-factory tool store; sentrux.log
Installed sentrux runs the structural gate and reports Quality: baseline -> current ✅ pass live sentrux gate --save . then sentrux gate . gave Quality: 3981 -&gt; 3981, 'No degradation detected', exit 0
Adversarial: a checksum mismatch aborts the install and installs nothing ✅ pass live Tampered sha256 gave 'checksum mismatch', exit 1, no ~/.local/bin created
Ansible apply on a clean host installs libgtk-3-0t64 and sentrux, and verify.yml confirms ~/.local/bin/sentrux ⏸️ untested no ansible-playbook and ansible are not on PATH. docker is installed but the daemon is unreachable (permission denied on /var/run/docker.sock), so tests/container-smoke.sh cannot build or run the…
  • python3 scripts/install_tools.py --home &lt;tmp&gt; --tools sentrux --resolve against live GitHub
  • python3 scripts/install_tools.py --home &lt;tmp&gt; --tools sentrux, run twice, into a disposable home
  • sentrux --version, sentrux gate --save . and sentrux gate . in a throwaway git repo
  • install with a tampered sha256 passed through --resolved
  • pytest tests/test_install_tools.py in a temporary venv
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

…fied

The fleet runs `sentrux gate .` every session, but Code-Factory installed no
sentrux, so on a fresh host the gate silently did not run.

scripts/install_tools.py installs sentrux as a core tool from the latest
sentrux/sentrux GitHub release (the source sentrux's own install.sh uses),
verified against the GitHub release-asset SHA-256 and linked into
~/.local/bin. The binary otherwise downloads its tree-sitter grammars itself,
unverified, on first run (even for --version); the installer installs the
same release's grammars-<platform>.tar.gz, also digest-verified, and links
each grammar into ~/.sentrux/plugins/<lang>/grammars/ so that never happens.
Both assets come from one /latest lookup per repository.

The only release binary links GTK 3 even for its CLI, so libgtk-3-0t64
joins the base packages. verify.yml checks ~/.local/bin/sentrux.
@undeemed
undeemed merged commit 0417b15 into main Oct 2, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant