Skip to content

fix(deploy): stop Start-Process from shredding the Linux Kit build command - #487

Merged
monkey1sai merged 5 commits into
mainfrom
fix/kit-repo-build-linux-arg-quoting
Aug 11, 2026
Merged

monkey1sai merged 5 commits into
mainfrom
fix/kit-repo-build-linux-arg-quoting

Conversation

@monkey1sai

@monkey1sai monkey1sai commented Aug 11, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • fix the Linux Kit build launch: Start-Process re-tokenizes its joined ArgumentList, so the quoted -c build command reached bash shredded — repo.sh ran with no arguments, printed usage, exited 0, and the build log redirect never happened
  • write the launch command into a wrapper script so the command line carries exactly one plain path argument no platform re-quoting can damage
  • fail closed when the build process exits 0 without creating its log file (the shredded-launch signature); a stale log from an earlier build is removed before launching so the guard proves this build wrote it
  • feed the wrapper to bash on stdin so the command line carries no argument at all — a deploy_root with spaces has nothing left to shred
  • latent since the Linux migration (feat(deploy): migrate the persistent test deploy area to remote Linux (PR-B) #467): every earlier rebuild found the deployment checkout unchanged and skipped the build phase; first fired on the post-feat(deploy): harden canonical Linux test deployment #484 fixpoint rebuild, which reset the checkout and cleaned _build

Change Classification

Item Result
Change lane G
Behavior contract changed no
Requirement source existing contract

Deploy Path Verification

Item Result
Affects runtime / docker / Kit / viewer / ports / env? yes — the Kit build phase of the canonical Linux deploy
Canonical deploy path updated? yes — scripts/lib/host-native-launcher.ps1 (Invoke-KitRepoBuild bash launch)
Deploy dry-run command not used: canonical rebuild contract forbids DryRun; the launch mechanism was verified by an isolated probe on the canonical Linux host (see Verification) and the full rebuild lands with the post-merge ledger fixpoint
Verify command remote isolated probe of the wrapper launch path; post-merge: scripts/dev/rebuild-test-deploy.ps1 -Build -InventoryPath <owner-private-inventory> + remote verify-all -Profile Deployment under the open ledger entry

AI Coding Governance

Item Result
Linked issue #494
Requirement source existing contract
CODEOWNERS / owner review exact-head approval required; current head fa0423c is awaiting review
GitNexus evidence UNKNOWN / unavailable — health report: overall_status=unhealthy, exact checkout trust unknown, canonical checkout missing; gitnexus detect-changes --scope compare --base-ref main failed on duplicate repo registrations; exact worktree -r failed as not indexed. Sol/max reviewer accepted this residual for commit/push only, not merge.
Browser E2E evidence not a frontend product change; browser/full-system E2E is not claimed
Agent workflow changed? no
Required checks expected PR metadata contract, changed-path CI jobs, self-referential debt gate, and local PR preflight

Windows On-Demand Verification

Item Result
Windows verification tier deploy_dryrun
Windows verification evidence exact head fa0423c4052e6c279e267427130eb4180817d52a; PS7 and Windows PowerShell 5.1 launcher suites PASS; root contracts 483 passed / 9 skipped using an isolated pytest temp root because the host shared temp ACL denied access; rebuild/test-deploy contracts, agent governance, PowerShell static, secret scan, and security exceptions PASS; git diff --check clean; exact-head CI run 31473397223 pending.

Self-Referential Bootstrap

Item Result
Self-referential bootstrap yes
Bootstrap ledger entry linux-test-deploy-verifier-hardening
Bootstrap reason This fixes a mechanism-path regression surfaced by that entry's own fixpoint rebuild: the canonical transport deploys only freshly fetched origin/main, so the repaired build launch cannot produce canonical post-change evidence before merge. The entry stays open; its fixpoint (14-command contract incl. canonical rebuild) runs after this merges.

Verification

  • scripts/tests/test-host-native-launcher.ps1: ALL PASSED under PS7 and Windows PowerShell 5.1 for exact head fa0423c — includes real Git Bash launch, special-character paths, exit-0-without-log, stale-log removal, locked stale-log cleanup failure, non-file log-path rejection, and metadata-error fail-closed guards
  • canonical Linux host isolated probe (same stdin-fed wrapper mechanism, fake repo.sh, run from a deploy root with spaces directory): exit 0, args seen=[build], log created with the script's stdout
  • python -m pytest tests -q -p no:cacheprovider: 483 passed, 9 skipped; test-rebuild-test-deploy, test-agent-governance-check, invoke-powershell-static, secret scan, security-exception policy: PASS; git diff --check clean
  • root-cause chain on the canonical host (2026-08-11): deploy.log shows [fix] running bim-streaming-server Kit build then [fail] Kit build completed but runtime artifacts are still missing 1.2s later; reproduction showed repo tool usage on the console (redirect lost) and ExitCode=0; with the wrapper the same host passes

🤖 Generated with Claude Code

https://claude.ai/code/session_015QTVFY89rS2xRwRB2TpFP6

Summary by CodeRabbit

  • Bug Fixes
    • Improved Linux Kit builds to reliably preserve build arguments, output redirection, and paths containing special characters.
    • Removed stale build logs before each run to prevent outdated results from being mistaken for current output.
    • Builds now fail when they report success but do not produce the expected build log.
    • Improved handling of empty control URLs and IPv6 loopback addresses across supported environments.

…mmand

The bash launch path passed the whole build command as one -c string
with embedded quotes. Start-Process joins its ArgumentList into a single
Arguments string and re-tokenizes it, so bash actually received only the
repo.sh path as the command: repo.sh printed its usage with no arguments
and exited 0, the build argument and the log redirect were silently
dropped, and deploy.ps1 took the fake exit 0 as a successful build until
the artifact recheck failed with a far less diagnosable message. This
was latent since the Linux migration (#467) — every earlier rebuild
found the deployment checkout unchanged and skipped the build phase —
and first fired on the post-#484 fixpoint rebuild, which reset the
checkout and cleaned _build.

Write the launch command into a wrapper script instead, so the command
line carries exactly one plain path argument that no platform's argument
re-quoting can damage. Also fail closed when the build process exits 0
without ever creating its log file: that combination means the launch
line was shredded and nothing ran.

Verified on the canonical Linux host (isolated probe): repo.sh received
exactly 'build', the redirect created the log, exit 0. The full canonical
rebuild through this path lands with the ledger fixpoint after merge.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QTVFY89rS2xRwRB2TpFP6
Copilot AI balanced review requested due to automatic review settings August 11, 2026 06:43
@coderabbitai

coderabbitai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Linux Kit builds now run through a generated Bash wrapper that preserves the build argument and output redirection. Invoke-KitRepoBuild removes stale logs and returns failure when a successful process does not create a new log. Tests cover launch behavior, log validation, and cross-runtime assertions.

Changes

Kit launch validation

Layer / File(s) Summary
Linux wrapper launch
scripts/lib/host-native-launcher.ps1, scripts/tests/test-host-native-launcher.ps1
Linux builds use a generated Bash wrapper. The wrapper preserves shell-sensitive paths, passes build, and redirects output to the requested log. The integration test skips when Bash is unavailable.
Build log validation
scripts/lib/host-native-launcher.ps1, scripts/tests/test-host-native-launcher.ps1
Each build removes an existing log before launch. A zero exit code becomes 1 when no new log exists. Tests cover successful log creation and missing logs.
Cross-runtime test compatibility
scripts/tests/test-host-native-launcher.ps1
Tests normalize empty Kit control URLs and validate IPv6 loopback addresses by parsed address semantics.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Possibly related PRs

Sequence Diagram(s)

sequenceDiagram
  participant InvokeKitRepoBuild
  participant Bash
  participant repo.sh
  participant BuildLog
  InvokeKitRepoBuild->>BuildLog: remove stale log
  InvokeKitRepoBuild->>Bash: launch generated wrapper
  Bash->>repo.sh: pass build argument
  repo.sh->>BuildLog: redirect build output
  InvokeKitRepoBuild->>BuildLog: verify new log exists
  InvokeKitRepoBuild-->>InvokeKitRepoBuild: return exit code or failure
Loading

Suggested reviewers: monkey1sai-blip

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main fix: preventing Start-Process from corrupting the Linux Kit build command.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/kit-repo-build-linux-arg-quoting

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/lib/host-native-launcher.ps1`:
- Around line 401-408: Remove any existing file at $LogPath before invoking
$StartProcessFn, while safely handling the file’s absence. Add a test covering a
pre-existing log where the simulated launch exits 0 without creating a new log,
and verify the launcher reports failure rather than accepting the stale file.

In `@scripts/tests/test-host-native-launcher.ps1`:
- Around line 205-216: Update the generated repo.sh setup in the test around
fakeRepoSh and WriteAllText to grant the file executable permission on Unix
hosts before Invoke-KitRepoBuild runs. Preserve the existing script contents and
test assertions, and use the platform-appropriate permission API.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 78790a33-b6a9-449e-a037-3f866f250578

📥 Commits

Reviewing files that changed from the base of the PR and between 5a7fea9 and af54c4a.

📒 Files selected for processing (2)
  • scripts/lib/host-native-launcher.ps1
  • scripts/tests/test-host-native-launcher.ps1

Comment thread scripts/lib/host-native-launcher.ps1
Comment thread scripts/tests/test-host-native-launcher.ps1

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: af54c4a0f0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/lib/host-native-launcher.ps1 Outdated
Comment thread scripts/tests/test-host-native-launcher.ps1

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a latent regression in the canonical Linux Kit build launch inside Invoke-KitRepoBuild. Previously the build was started with Start-Process -FilePath 'bash' -ArgumentList @('-c', $bashCommand), but Start-Process re-joins and re-tokenizes ArgumentList, shredding the quoted -c string so repo.sh ran with no arguments (printed usage, exited 0, and the log redirect never happened). The build phase then silently "succeeded" until the later artifacts check failed with a hard-to-diagnose error. The fix writes the full launch command into a wrapper script and passes only that single plain path to bash, plus adds a fail-closed guard that treats exit 0 with no log file as a failure.

Changes:

  • Launch the Linux repo.sh build through a generated kit-repo-build-launch.sh wrapper (one plain path argument) instead of a re-tokenizable bash -c command string.
  • Fail closed in Invoke-KitRepoBuild when the process exits 0 but never created its log file.
  • Add regression tests: Test 13 now requires the success fake to create its log; Test 15b pins exit-0-without-log to fail closed; Test 15c drives the real bash launch path.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
scripts/lib/host-native-launcher.ps1 Replaces the shredded bash -c launch with a wrapper-script indirection and adds the exit-0-without-log fail-closed guard.
scripts/tests/test-host-native-launcher.ps1 Updates Test 13 and adds Tests 15b/15c to cover the fail-closed guard and the real bash launch path; Test 15c creates a fake repo.sh without an execute bit, which fails the exec on POSIX hosts.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread scripts/tests/test-host-native-launcher.ps1 Outdated
…is launch

Review round: feed the wrapper script to bash on stdin so the command
line carries no argument at all — a deploy_root with spaces has nothing
left to shred. Remove any stale kit-repo-build.log before launching so
the exit-0-must-have-a-log guard proves this build created it, not an
earlier one. Mark the test fixture repo.sh executable on POSIX hosts
where exec would otherwise fail with EACCES, and run the dynamic bash
test inside a directory with spaces.

Verified again on the canonical Linux host: exit 0, args seen=[build],
log created, from a 'deploy root with spaces' directory.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015QTVFY89rS2xRwRB2TpFP6

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7925fe7792

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/lib/host-native-launcher.ps1 Outdated
Comment thread scripts/lib/host-native-launcher.ps1
Comment thread scripts/lib/host-native-launcher.ps1
monkey1sai and others added 2 commits August 11, 2026 15:29
The registry accepts deploy_root values containing $ and backtick; embedding
those raw inside the wrapper's double-quoted sh strings lets the shell perform
parameter/command substitution on the path, so exec or the log redirect targets
a different location. Escape the four double-quote-special characters when
composing the wrapper, and run Test 15c from a directory carrying spaces, $,
and a backtick (fails with exit 127 without the escaping).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018Gn3PJQ96Krb3adAErpXGu

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/lib/host-native-launcher.ps1`:
- Around line 403-405: The stale-log cleanup before invoking $StartProcessFn
must fail closed: update Remove-Item for $LogPath to stop on errors, then
explicitly verify the path is absent before proceeding. Ensure any cleanup
failure prevents launch and add a regression test covering an undeletable or
still-present $LogPath.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 8c7667ae-80fc-42ee-b698-a022cc8e6b68

📥 Commits

Reviewing files that changed from the base of the PR and between af54c4a and 4e5210d.

📒 Files selected for processing (2)
  • scripts/lib/host-native-launcher.ps1
  • scripts/tests/test-host-native-launcher.ps1
🚧 Files skipped from review as they are similar to previous changes (1)
  • scripts/tests/test-host-native-launcher.ps1

Comment thread scripts/lib/host-native-launcher.ps1 Outdated

@monkey1sai-blip monkey1sai-blip left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Scripted approval carrying the operator's authority for the documented one-time governance exception on PR #487. This is not independent human review or human sign-off. Exact head fa0423c; required branch-protection contexts completed as success/skipped. The non-required governance diagnostics and unresolved bootstrap thread remain disclosed and are accepted only for this PR because issue #494 proves the current repair-lane deadlock. AI-assisted changes received Luna, Terra, and Sol/max adversarial verification.

@monkey1sai
monkey1sai merged commit 31a9fa3 into main Aug 11, 2026
35 of 41 checks passed
@monkey1sai
monkey1sai deleted the fix/kit-repo-build-linux-arg-quoting branch August 11, 2026 08:47
monkey1sai added a commit that referenced this pull request Aug 12, 2026
…with its rebuild-backed fixpoint (#499)

* fix(governance): close the linux-test-deploy-verifier-hardening debt with its rebuild-backed fixpoint

Rerun the entry's ordered 14-command verification contract after #487 merged:
local suites 1-11 all exit 0, canonical Linux rebuild exit 0 with the repaired
stdin-fed build launch proven on the canonical host (deploy tag
deploy-20260811-639220482065640754-003), the CAD hardener idempotently exit 0,
and the remote Deployment-profile verify all green. Two group-writable
directory drifts the #484 trust-root ancestry validation correctly refused are
recorded in the summary with their in-run chmod remediation.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018Gn3PJQ96Krb3adAErpXGu

* docs(evidence): attest the strict contract-order fixpoint sweep

Rerun the full 14-command contract in the opening contract's exact order
(1-11 local at the deployed source commit c88dca6, then harden 12, rebuild 13
with deploy tag deploy-20260811-639220494716638402-004, verify 14) after review
flagged the first sweep's 13-before-12 chronology; every command exit 0 in a
single pass. The first sweep and the in-run permission findings remain recorded
as context.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018Gn3PJQ96Krb3adAErpXGu

* docs(evidence): declare an allowed document nature and add run timestamps

working note replaces the non-vocabulary 'evidence' nature per docs/AGENTS.md,
and the attested-run section now carries UTC time anchors proving the
12-before-13 execution order.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018Gn3PJQ96Krb3adAErpXGu

* docs(evidence): rerun command 14 with the pinned -InventoryPath invocation

The immutable command map pins canonical-linux-deployment-verify as
verify-all.ps1 -Profile Deployment -InventoryPath <owner-private-inventory>;
the sweep had substituted the environment-variable inventory form. Rerun the
pinned invocation against the same unchanged -004 deployment (exit 0, all six
checks Passed, 2026-08-12T02:00:16Z) and make it the attested record.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018Gn3PJQ96Krb3adAErpXGu

* fix(governance): attest the fixpoint with a pinned-form 12-14 remediation rerun

Review P1 on this PR proved command 13's recorded invocation carried an
extra -IdentityFile beyond the immutable command map's pinned form. The
owner moved the deploy key into default ssh resolution (batch-mode
preflight DEFAULT_IDENTITY_OK), then commands 12-14 were rerun in contract
order, all pinned form, single pass:

- 12 harden-cad on the remote deploy_root: exact schema line, exit 0
- 13 rebuild from fresh origin/main (970dc34, isolated worktree), NO
  -IdentityFile / -TargetId: deploy exit 0, tag
  deploy-20260812-639221007059362180-001 pushed
- 14 verify-all -Profile Deployment -InventoryPath on the NEW deployment:
  six checks Passed, none Failed, exit 0

summary.md keeps the 2026-08-11 invocation as a historical record and
marks the 2026-08-12 rerun as the attested one; ledger fixpoint
reverified_at rebound to 2026-08-12T03:07:00Z.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants