build(rust): pin all product and release lanes to 1.97.1 - #944
build(rust): pin all product and release lanes to 1.97.1#944seonghobae wants to merge 77 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent Repair the exact current-head BandScope-owned quickcheck failure on the existing |
|
@opencode-agent repair Fresh 2026-08-25 refetch still shows the canonical branch Update only the stale occurrences inside these seven tests:
There are 11 stale Then run the focused |
|
@opencode-agent repair Fresh writer-lease refetch: PR #944 is still exactly Current exact RED remains CI run
Change only the 11 Verification-before-completion: run the focused |
|
@OpenCode Use This exact head still has the BandScope-owned deterministic quickcheck defect already proven by CI run Repair only the stale test contract in the seven known scopes: replace only their obsolete Rust-audit fixture/expected-violation occurrences with |
|
Fresh cross-lane evidence for this PR's canonical Rust CI/test ownership: exact #1040 head First causal boundary on current protected workflow: This is a BandScope-owned Rust evidence gap, and #944 already owns |
|
@OpenCode Use This writer has now repaired the previously identified Rust evidence gap on the same branch: The remaining known deterministic BandScope-owned quickcheck defect is the old test-contract drift in TDD/verification: first show the focused stale assertions fail against the pinned production workflow if still reproducible; apply only the scoped test repair; run the focused policy test file, |
|
@opencode-agent Repair and restack the existing canonical Rust-toolchain branch only; do not create a new PR and do not force-push. Fresh authority: protected |
Problem
BandScope's Rust-backed analysis build, Tauri validation, release preflight, dependency audit, and native packaging lanes must use one reviewed compiler and must not be able to manufacture compiler/test evidence from non-executing or failure-masked shell text.
Rust
1.97.1is the reviewed repository build baseline. Floatingstableselection can change scientific, security, and release evidence without a repository diff.Exact current identity
develop@749511c3ad4000090048718f685c6bee6b3d2c25.926296fe8fdb145d0c7b7d0cc9c3fc41fb3cb484.agent/rust-toolchain-refresh-2026-08-19.developafter ordinary non-force reconciliation plus the product/technical gap baseline; no force-push or destructive rebase was used.Current contract
rust-toolchain.tomlpins Rust1.97.1;rust-toolchainupdate discovery targets protecteddevelop;scripts/checks/verify_rust_toolchain.pyrejects floating selectors and evidence borrowed across Dependabot lanes, workflow files, sibling jobs, comments, step names, environment text, or other non-executing YAML;--manifest-path,--locked, or explicit target triples, but may not use shell chaining/pipelines/background control operators that can replace the required command's exit status; andTest-first and concurrency repair
Earlier TDD on this branch closed cross-Dependabot-lane, comment-only field, cross-workflow, cross-native-job, non-executable-
run, failure-masked shell, and workflow evidence-authority gaps.The seven stale supply-chain policy tests that still encoded
cargo +stable auditwere repaired on the canonical branch atba4e7c1508261f7478e16810f67e1b0b44768a8b: only the 11 stale audit-command occurrences in the affected test scopes were changed tocargo +1.97.1 audit, while intentional floating-selector rejection cases remained. The temporary self-modifying repair workflow/script were removed after that repair landed.Protected
developsubsequently advanced with buyer-visible first-playable-range work and npm/runtime/supply-chain hardening. Rather than overwrite that concurrent work, this branch re-fetched currentdevelop, reconciled the five overlapping workflow/CHANGELOG files by intent, preserved the current npm10.9.9/Corepack/tar validation and artifact-upload behavior, then appended the ordinary two-parent reconciliation commit762cdfec70df2be27f38d263bf9a4e0c6a6063c0withdevelop@749511c3ad4000090048718f685c6bee6b3d2c25as its second parent.docs/product-technical-gap-baseline.mdwas then added at the current branch tip to preserve buyer PRD/TRD, DDD context map and ubiquitous language, persistence/ERD applicability, exact-head evidence, organization naming status, current gap ledger, and security/test/operability merge conditions in repository-owned documentation.Verification status
All predecessor-head CI evidence is stale for merge purposes. Fresh checks must bind to exact head
926296fe8fdb145d0c7b7d0cc9c3fc41fb3cb484. Any failing current-head job must be RCA'd from its exact log and repaired on this branch or its true causal owner.Canonical JavaScript dependency/security owner #783 is already merged as
7ad56cf0065d068ec6463d92726de4855a6e201dand is an ancestor of the reconciled protected base. Its npm/PDF.js/Nanoid/Undici and lock-generator protections are therefore inherited here rather than a remaining dependency blocker.Merge gate
Keep Draft and unmerged until one unchanged exact head has every applicable repository and central CI/build/release/security/SAST/SBOM/supply-chain/coverage/review gate terminal-success, zero valid unresolved findings remain, a qualifying independent non-author approval is current for the last push, and ordinary protected-branch rules permit merge without bypass. Queued, pending, skipped-required, failed, stale, predecessor-head, protected-base, model-only, self/author, or administrative-bypass evidence is non-passing.