Skip to content

ci: reuse cargo-component installer in live canary - #5101

Open
theredspoon wants to merge 6 commits into
nearai:mainfrom
theredspoon:codex/upstream-live-canary-cargo-component
Open

theredspoon wants to merge 6 commits into
nearai:mainfrom
theredspoon:codex/upstream-live-canary-cargo-component

Conversation

@theredspoon

@theredspoon theredspoon commented Jun 20, 2026 •

Copy link
Copy Markdown

Summary

  • Replace live-canary cargo install cargo-component --locked || true source installs with pinned taiki-e/install-action usage.
  • Keep the existing local composite installer only in lower-privilege live-canary lanes.
  • Call the pinned upstream installer directly in live-secret/self-hosted lanes so PR-controlled repo-local action code is not executed at the privileged boundary.
  • Remove the remaining swallowed cargo-component install failure in the Reborn WebUI v2 live QA lane.
  • Add actionlint configuration for the documented ironclaw-live self-hosted runner label and clean up provider env writes so plain actionlint passes.
  • Resolve setup-sccache-dist from a canonical (default-branch) checkout in prepare-reborn-webui-v2-live-qa instead of the PR-controlled checkout, closing a supply-chain gap where a same-repo branch could swap in malicious composite-action code with secrets in scope (79158f92e).

Change Type

CI / workflow hardening.

Linked Issue

None.

Test Strategy

User behavior: Not applicable: this is a CI/workflow-only change (.github/workflows/live-canary.yml, .github/actionlint.yaml); no user-facing behavior is affected.

Risk areas:

  • Security or permissions (trust boundary: which live-canary lanes execute repo-local composite-action code vs. the pinned upstream action; see Security Impact below)
  • Model behavior
  • Browser
  • Side effect
  • Persistence
  • External provider
  • Cross-component behavior

Tests added or updated:

  • Unit or contract: Not applicable: no Rust code changed.
  • Reborn integration: Not applicable: no Reborn code changed.
  • Recorded fixture: Not applicable.
  • Browser E2E: Not applicable.
  • Backend or runtime: Not applicable.
  • Live canary: No new automated test added (GitHub Actions workflow YAML has no unit-test harness). Validated via YAML syntax check, actionlint, and a manual checkout ref: audit across every live-canary job (see Review Track below) confirming which jobs resolve action code from a PR-influenceable ref vs. a canonical/default-branch ref.

What the tests prove: The workflow YAML is syntactically valid, actionlint passes cleanly, and the manual audit confirms no privileged (live-secret / self-hosted) lane resolves action code from a PR-controlled checkout.

Commands run:

  • git diff --check -- .github/workflows/live-canary.yml .github/actionlint.yaml
  • ruby -e 'require "yaml"; YAML.load_file(".github/workflows/live-canary.yml"); YAML.load_file(".github/actionlint.yaml"); puts "yaml ok"'
  • actionlint .github/workflows/live-canary.yml
  • rg -n "Install cargo-component|cargo install cargo-component|install-cargo-component|taiki-e/install-action" .github/workflows/live-canary.yml

Security Impact

Positive. Privileged lanes (live-secret / self-hosted) invoke the pinned upstream taiki-e/install-action directly rather than a repo-local composite, and setup-sccache-dist is now resolved from a canonical checkout rather than the PR-controlled ref, removing a path for a same-repo branch to run malicious composite-action code with SCCACHE_DIST_AUTH_TOKEN and the OVH Redis SSH key in scope.

Reborn Trust-Boundary Checklist

N/A: this PR only touches CI workflow configuration (.github/workflows/live-canary.yml, .github/actionlint.yaml). It adds or modifies no Reborn runtime/policy/evidence/trust-bearing types, prompt-construction paths, hashing, status/exit/policy variants, serde(default) fields, queues/buffers, or sandboxed driver code, so these checklist items don't apply. The GitHub Actions trust boundary this PR does affect (privileged live-secret/self-hosted lanes must not execute repo-local composite-action code resolved from a PR-controlled checkout) is covered under Security Impact and Review Track.

Database Impact

None.

Blast Radius

Limited to .github/workflows/live-canary.yml (still the only file this PR touches). The workflow change affects cargo-component installation before WASM extension/channel builds in live-canary lanes, plus the checkout used to resolve setup-sccache-dist in prepare-reborn-webui-v2-live-qa. A subsequent upstream/main merge (see Review Track) removed the provider-matrix job upstream, which also removed this PR's own cargo-component change to that job; the file is no longer byte-for-byte a superset of the pre-merge diff, but no other job's content from this PR was affected.

Rollback Plan

Revert this PR to return live-canary cargo-component installation, actionlint config, and the sccache checkout to the previous workflow behavior.

Review Follow-Through

  • Branch was brought up to date with upstream/main (d8be0c0de, the Waves 0-4 batch) via a merge commit rather than a rebase; .github/workflows/live-canary.yml was untouched by that upstream commit.
  • CodeRabbit's composite-action-duplication finding (six jobs "duplicating" the composite instead of calling it) was reviewed against a checkout-ref audit and found to be a false positive: those jobs deliberately call the pinned upstream action directly to avoid running repo-local composite code at the privileged trust boundary. CodeRabbit withdrew the finding after this was explained; the review thread is marked resolved.
  • The real setup-sccache-dist supply-chain finding (PR-controlled checkout resolving a secrets-touching composite action) was fixed via a canonical-checkout step (79158f92e).
  • The 341-file merge triggered a fresh full CodeRabbit review (started 2026-08-04T23:57 UTC, completed ~2026-08-05T01:00 UTC). Its only finding was a Description-check warning (this PR body was missing the Test Strategy and Reborn Trust-Boundary Checklist sections), now addressed by this edit. No new code findings.
  • ilblackdragon's 2026-07-04 APPROVE predates the 341-file merge, and was posted as a plain issue comment rather than a formal GitHub review, so it never registered against branch protection. theredspoon re-requested a formal review from @ilblackdragon on 2026-08-05T03:51:56Z, explaining this distinction and noting the PR had drifted ~610 commits behind upstream/main by that point. No reply from ilblackdragon since. The branch has since taken a second upstream/main merge (bc04fe816, 2026-08-05T22:23:50-03:00) plus the crash-safe cleanup follow-up below (f62d9e7d3, 2026-08-05T22:54:56-03:00); branch protection still shows REVIEW_REQUIRED with no formal approval on record. Current drift vs upstream/main is 54 commits.

Review Track

CI/security review. Current head is 4845ffa84 (a third upstream/main merge, 0 commits behind upstream/main; previous head f62d9e7d3 was the follow-up fix making the canonical-checkout cleanup crash-safe). This merge resolved a modify/delete conflict: upstream commit 226bd491d (#7418) deleted the provider-matrix job entirely (job body, weekly cron trigger, workflow_dispatch dropdown option, canary-report's dependency on it, and its zizmor pre-install steps), while this branch had independently repointed that same job's cargo-component install to the pinned taiki-e/install-action. Resolution took upstream's deletion as-is rather than resurrecting the job; the four remaining privileged lanes (public-smoke, persona-rotating, private-oauth, release-public-full) still call the pinned installer directly and the two non-privileged lanes (workflow-canary, deterministic-replay) still use the local composite, so this PR's own substance is otherwise unaffected. PR is MERGEABLE. mergeStateStatus is BLOCKED pending a fresh approving review: the 2026-07-04 "APPROVE" from ilblackdragon was posted as a plain issue comment, not a formal GitHub review, so it never registered against branch protection. theredspoon explicitly re-requested review from @ilblackdragon on 2026-08-05T03:51:56Z, explaining the informal-comment-vs-formal-review distinction and noting the ~610-commit drift at that time; no reply yet. Main point to check is that privileged lanes use pinned action code directly and resolve secrets-touching composites from a canonical checkout, while lower-privilege lanes may continue using the repo-local composite.

Validation

  • git diff --check -- .github/workflows/live-canary.yml .github/actionlint.yaml
  • ruby -e 'require "yaml"; YAML.load_file(".github/workflows/live-canary.yml"); YAML.load_file(".github/actionlint.yaml"); puts "yaml ok"'
  • actionlint .github/workflows/live-canary.yml
  • rg -n "Install cargo-component|cargo install cargo-component|install-cargo-component|taiki-e/install-action" .github/workflows/live-canary.yml

Follow-up: canonical-checkout cleanup made crash-safe

  • The Remove canonical action checkout step in prepare-reborn-webui-v2-live-qa only ran if: steps.lookup.outputs.found != '1', so it was skipped whenever the preceding secrets-touching setup-sccache-dist step failed.
  • Low-impact today since this job runs on an ephemeral GitHub-hosted runner that's torn down regardless, but the same workflow also has a persistent self-hosted runner elsewhere with no cross-run cleanup, so this was fixed defensively now rather than left for later.
  • Added always() to the step's condition (if: always() && steps.lookup.outputs.found != '1') so cleanup of .canonical-live-canary-actions runs unconditionally, alongside its existing guard.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@github-actions github-actions Bot added scope: ci CI/CD workflows size: S 10-49 changed lines labels Jun 20, 2026
@coderabbitai

coderabbitai Bot commented Jun 20, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • Chores
    • Standardized build setup across live testing and release workflows for more consistent execution.
    • Pinned component tooling versions in applicable build lanes to improve reproducibility.
    • Improved fallback build reliability by using shared, canonical build tooling.
    • Streamlined environment configuration across provider test scenarios.
    • Added validation settings for the designated self-hosted runner.

Walkthrough

Live-canary jobs replace inline cargo-component installation, update Reborn WebUI v2 fallback sccache loading, and add Actionlint configuration for the ironclaw-live runner.

Changes

CI workflow updates

Layer / File(s) Summary
Shared and pinned install steps
.github/workflows/live-canary.yml
workflow-canary and deterministic-replay use the shared local installer action. Four other lanes use taiki-e/install-action pinned to cargo-component@0.21.1.
Canonical sccache fallback
.github/workflows/live-canary.yml
The Reborn WebUI v2 fallback checks out the default branch to load the canonical sccache action, then removes the temporary checkout.
Self-hosted runner configuration
.github/actionlint.yaml
The configuration sets the self-hosted runner label to ironclaw-live and sets config-variables to null.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers: serrrfirat

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title uses Conventional Commits style and accurately describes the live-canary cargo-component installer change.
Description check ✅ Passed The description covers the change, validation, security impact, blast radius, rollback, review track, and test strategy with relevant CI details.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added risk: medium Business logic, config, or moderate-risk modules contributor: new First-time contributor labels Jun 20, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/live-canary.yml (1)

477-478: 🔒 Security & Privacy | 🔴 Critical | ⚡ Quick win

Do not run a repo-local action from the checked-out ref in these privileged lanes.

These steps now execute ./.github/actions/install-cargo-component from whatever ref was checked out. In public-smoke, persona-rotating, private-oauth, and provider-matrix, that means branch-controlled action code runs before or alongside live secrets; private-oauth also does it on the ironclaw-live self-hosted runner. Call the pinned upstream action directly here instead of routing through a workspace-local composite.

Suggested fix
       - name: Install cargo-component
-        uses: ./.github/actions/install-cargo-component
+        uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2
+        with:
+          tool: cargo-component@0.21.1

As per path instructions, .github/workflows/**: "flag privileged workflows that check out or execute PR-controlled code".

Also applies to: 793-794, 849-850, 901-902

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/live-canary.yml around lines 477 - 478, This workflow step
is executing the repo-local install-cargo-component composite from the
checked-out ref in privileged lanes, which allows PR-controlled code to run near
live secrets. Update the affected jobs (public-smoke, persona-rotating,
private-oauth, and provider-matrix) to call the pinned upstream cargo-component
action directly instead of uses: ./.github/actions/install-cargo-component,
keeping the workflow on trusted, version-pinned action code only.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/live-canary.yml:
- Around line 693-695: The `Install cargo-component` step is still swallowing
failures with `|| true`, which breaks the fail-fast behavior for
`reborn-webui-v2-live-qa`. Remove the fallback so the `cargo install
cargo-component` command in this workflow step fails the job immediately if
installation breaks, keeping the subsequent `Build WASM channels` step from
masking the real issue.

---

Outside diff comments:
In @.github/workflows/live-canary.yml:
- Around line 477-478: This workflow step is executing the repo-local
install-cargo-component composite from the checked-out ref in privileged lanes,
which allows PR-controlled code to run near live secrets. Update the affected
jobs (public-smoke, persona-rotating, private-oauth, and provider-matrix) to
call the pinned upstream cargo-component action directly instead of uses:
./.github/actions/install-cargo-component, keeping the workflow on trusted,
version-pinned action code only.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 68ee2bae-040c-4b70-9fc9-ee4145c3966e

📥 Commits

Reviewing files that changed from the base of the PR and between a1ae1d0 and 1e13976.

📒 Files selected for processing (1)
  • .github/workflows/live-canary.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/live-canary.yml (1)

477-478: 🔒 Security & Privacy | 🔴 Critical | ⚡ Quick win

Do not run a repo-local action from the checked-out ref in these privileged lanes.

These steps now execute ./.github/actions/install-cargo-component from whatever ref was checked out. In public-smoke, persona-rotating, private-oauth, and provider-matrix, that means branch-controlled action code runs before or alongside live secrets; private-oauth also does it on the ironclaw-live self-hosted runner. Call the pinned upstream action directly here instead of routing through a workspace-local composite.

Suggested fix
       - name: Install cargo-component
-        uses: ./.github/actions/install-cargo-component
+        uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2
+        with:
+          tool: cargo-component@0.21.1

As per path instructions, .github/workflows/**: "flag privileged workflows that check out or execute PR-controlled code".

Also applies to: 793-794, 849-850, 901-902

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/live-canary.yml around lines 477 - 478, This workflow step
is executing the repo-local install-cargo-component composite from the
checked-out ref in privileged lanes, which allows PR-controlled code to run near
live secrets. Update the affected jobs (public-smoke, persona-rotating,
private-oauth, and provider-matrix) to call the pinned upstream cargo-component
action directly instead of uses: ./.github/actions/install-cargo-component,
keeping the workflow on trusted, version-pinned action code only.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/live-canary.yml:
- Around line 693-695: The `Install cargo-component` step is still swallowing
failures with `|| true`, which breaks the fail-fast behavior for
`reborn-webui-v2-live-qa`. Remove the fallback so the `cargo install
cargo-component` command in this workflow step fails the job immediately if
installation breaks, keeping the subsequent `Build WASM channels` step from
masking the real issue.

---

Outside diff comments:
In @.github/workflows/live-canary.yml:
- Around line 477-478: This workflow step is executing the repo-local
install-cargo-component composite from the checked-out ref in privileged lanes,
which allows PR-controlled code to run near live secrets. Update the affected
jobs (public-smoke, persona-rotating, private-oauth, and provider-matrix) to
call the pinned upstream cargo-component action directly instead of uses:
./.github/actions/install-cargo-component, keeping the workflow on trusted,
version-pinned action code only.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 68ee2bae-040c-4b70-9fc9-ee4145c3966e

📥 Commits

Reviewing files that changed from the base of the PR and between a1ae1d0 and 1e13976.

📒 Files selected for processing (1)
  • .github/workflows/live-canary.yml
🛑 Comments failed to post (1)
.github/workflows/live-canary.yml (1)

693-695: 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win

Stop swallowing cargo-component install failures in this lane.

Line 695 still keeps || true, so reborn-webui-v2-live-qa can mask a broken install and fail later in Build WASM channels with a worse error. That leaves this job out of the new fail-fast contract the shared installer was meant to enforce.

Suggested fix
       - name: Install cargo-component
         if: steps.resolve_reborn_webui_v2_cases.outputs.skip_shard != '1'
-        run: cargo install cargo-component --locked || true
+        uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2
+        with:
+          tool: cargo-component@0.21.1
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

      - name: Install cargo-component
        if: steps.resolve_reborn_webui_v2_cases.outputs.skip_shard != '1'
        uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2
        with:
          tool: cargo-component@0.21.1
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/live-canary.yml around lines 693 - 695, The `Install
cargo-component` step is still swallowing failures with `|| true`, which breaks
the fail-fast behavior for `reborn-webui-v2-live-qa`. Remove the fallback so the
`cargo install cargo-component` command in this workflow step fails the job
immediately if installation breaks, keeping the subsequent `Build WASM channels`
step from masking the real issue.

@github-actions github-actions Bot added size: M 50-199 changed lines and removed size: S 10-49 changed lines labels Jul 2, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/live-canary.yml:
- Around line 478-480: The workflow jobs are duplicating the cargo-component
install action instead of reusing the shared composite action, which breaks the
single-source-of-truth pinning. Update each affected job in live-canary.yml to
call ./.github/actions/install-cargo-component rather than inlining
taiki-e/install-action and cargo-component@0.21.1, matching the existing usage
in workflow-canary and deterministic-replay so future version bumps only change
one place.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 24cce5e9-e94c-4ed1-8af6-afeff05c4032

📥 Commits

Reviewing files that changed from the base of the PR and between 1e13976 and 096805e.

📒 Files selected for processing (1)
  • .github/workflows/live-canary.yml

Comment thread .github/workflows/live-canary.yml
@theredspoon
theredspoon force-pushed the codex/upstream-live-canary-cargo-component branch from 74ca27b to 359c49b Compare July 2, 2026 03:12

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/actionlint.yaml (1)

1-6: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Runner label matches usage; config-variables: null disables vars-context validation.

Label ironclaw-live correctly lines up with runs-on: [self-hosted, ironclaw-live] in private-oauth. Setting config-variables: null means actionlint stops checking ${{ vars.* }} refs (e.g. AUTH_LIVE_GITHUB_OWNER, AUTH_LIVE_NOTION_QUERY) against a known list — fine for suppressing false positives, but note it also silences genuine typo detection on vars.* names going forward.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/actionlint.yaml around lines 1 - 6, The runner label configuration
under self-hosted-runner already matches the workflow usage, but
config-variables: null disables actionlint validation for vars.* references.
Update the actionlint config to keep the ironclaw-live label mapping while
replacing the null vars setting with an explicit allowed variables list if you
want typo detection to continue working for AUTH_LIVE_GITHUB_OWNER,
AUTH_LIVE_NOTION_QUERY, and similar references.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/actionlint.yaml:
- Around line 1-6: The runner label configuration under self-hosted-runner
already matches the workflow usage, but config-variables: null disables
actionlint validation for vars.* references. Update the actionlint config to
keep the ironclaw-live label mapping while replacing the null vars setting with
an explicit allowed variables list if you want typo detection to continue
working for AUTH_LIVE_GITHUB_OWNER, AUTH_LIVE_NOTION_QUERY, and similar
references.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 12800527-3ad7-49be-a7ff-225c6e698a92

📥 Commits

Reviewing files that changed from the base of the PR and between 096805e and 74ca27b.

📒 Files selected for processing (2)
  • .github/actionlint.yaml
  • .github/workflows/live-canary.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (1)
.github/workflows/live-canary.yml (1)

478-480: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Duplicated inline installer, likely intentional — but drift risk remains.

This matches a prior review comment about 6 jobs duplicating taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2 (cargo-component@0.21.1) instead of calling ./.github/actions/install-cargo-component. Per the PR objective, this is now deliberate: privileged/self-hosted lanes call the pinned upstream installer directly so repo-local composite-action code isn't executed at the privileged boundary (relevant since reborn-webui-v2-live-qa can check out an attacker-influenced target_ref, lines 617-646). That rationale is sound for the security boundary.

However, the DRY problem it reintroduces (version bump now touches 7 files) is still real and separable from the trust boundary. Consider pinning the version once via a workflow-level env: and referencing it in each inline step, keeping the direct-to-upstream call but restoring single-source version control:

♻️ Reduce version drift while keeping the direct upstream call
 env:
+  CARGO_COMPONENT_VERSION: cargo-component@0.21.1
   ...
 
       - name: Install cargo-component
         uses: taiki-e/install-action@62b0f2dec647a8e604c6a0fda0e38530180dce20 # v2
         with:
-          tool: cargo-component@0.21.1
+          tool: ${{ env.CARGO_COMPONENT_VERSION }}

As per path instructions for .github/workflows/**, flag unpinned/duplicated third-party action usage that undercuts single-source-of-truth pinning.

Also applies to: 697-699, 798-800, 856-858, 910-912, 980-982

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/live-canary.yml around lines 478 - 480, The inline
`taiki-e/install-action` steps are intentionally kept for the privileged lanes,
but the repeated pinned version in `live-canary.yml` creates drift risk when
updating `cargo-component@0.21.1`. Keep the direct upstream installer in place
for the security boundary, but centralize the version in a workflow-level `env`
or similar single source and reference it from each install step so the pinned
`install-action` value is updated once. Use the duplicated install blocks around
the `cargo-component` setup steps as the target for the refactor.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Duplicate comments:
In @.github/workflows/live-canary.yml:
- Around line 478-480: The inline `taiki-e/install-action` steps are
intentionally kept for the privileged lanes, but the repeated pinned version in
`live-canary.yml` creates drift risk when updating `cargo-component@0.21.1`.
Keep the direct upstream installer in place for the security boundary, but
centralize the version in a workflow-level `env` or similar single source and
reference it from each install step so the pinned `install-action` value is
updated once. Use the duplicated install blocks around the `cargo-component`
setup steps as the target for the refactor.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 9bc4b25e-6ecc-4369-b733-b30db4e311d8

📥 Commits

Reviewing files that changed from the base of the PR and between 74ca27b and 359c49b.

📒 Files selected for processing (2)
  • .github/actionlint.yaml
  • .github/workflows/live-canary.yml

@ilblackdragon
ilblackdragon force-pushed the codex/upstream-live-canary-cargo-component branch from 359c49b to 9f03fdb Compare July 4, 2026 01:21
@ironloopai

ironloopai Bot commented Jul 4, 2026

Copy link
Copy Markdown
Contributor

IronLoop Review Status

Head: 9f03fdbf03a78025df27f022d25dbce057e0874d
Updated: 2026-07-04T01:21:58.003Z
Admission: webhook accepted the request and IronLoop persisted review state before this projection.

Current reviewers:

Reviewer State What it means Last update
none Queued No reviewer jobs scheduled yet. n/a

Recent activity:

Time Reviewer State Detail
n/a n/a Waiting No progress events recorded yet.

Commands:

  • @ironloop review
  • @ironloop review <agent-alias>
  • @ironloop status

@ilblackdragon

Copy link
Copy Markdown
Member

Reviewed and rebased onto current main (verdict: APPROVE).

Clean CI hardening: replaces cargo install cargo-component --locked || true (swallowed install failures) with the pinned taiki-e/install-action@62b0f2d # v2 (cargo-component@0.21.1) in the privileged live-secret/self-hosted lanes, and keeps the repo-local composite ./.github/actions/install-cargo-component only in the lower-privilege lanes — so PR-controlled action code never runs at the privileged boundary. Also adds .github/actionlint.yaml for the ironclaw-live self-hosted label.

  • Rebased with no conflicts; YAML parses; all 8 install steps intact (2 composite + 6 pinned upstream); the referenced composite action exists on main.
  • Not superseded.

Ready for a maintainer merge.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/live-canary.yml:
- Around line 736-752: The issue is that `setup-sccache-dist` is still
referenced from the PR checkout, so the workflow can execute untrusted composite
action changes with sensitive secrets in scope. Update the `Setup OVH sccache`
steps in `live-canary.yml` to use the canonical harness checkout for
`setup-sccache-dist`, matching the existing pattern used for restored `scripts/`
and `tests/e2e`, and apply the same fix to the repeated occurrence later in the
workflow. Ensure the action reference is resolved from the trusted canonical
source rather than `./.github/actions/setup-sccache-dist` in the PR tree.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 3a813490-f71d-4227-ab1e-3d4b7f815c0d

📥 Commits

Reviewing files that changed from the base of the PR and between 359c49b and 9f03fdb.

📒 Files selected for processing (2)
  • .github/actionlint.yaml
  • .github/workflows/live-canary.yml

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/live-canary.yml:
- Around line 736-752: The issue is that `setup-sccache-dist` is still
referenced from the PR checkout, so the workflow can execute untrusted composite
action changes with sensitive secrets in scope. Update the `Setup OVH sccache`
steps in `live-canary.yml` to use the canonical harness checkout for
`setup-sccache-dist`, matching the existing pattern used for restored `scripts/`
and `tests/e2e`, and apply the same fix to the repeated occurrence later in the
workflow. Ensure the action reference is resolved from the trusted canonical
source rather than `./.github/actions/setup-sccache-dist` in the PR tree.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 3a813490-f71d-4227-ab1e-3d4b7f815c0d

📥 Commits

Reviewing files that changed from the base of the PR and between 359c49b and 9f03fdb.

📒 Files selected for processing (2)
  • .github/actionlint.yaml
  • .github/workflows/live-canary.yml
🛑 Comments failed to post (1)
.github/workflows/live-canary.yml (1)

736-752: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Inspect the composite action to assess what it executes and whether it touches secrets/untrusted refs.
fd -HI 'action.yml|action.yaml' .github/actions/setup-sccache-dist
cat .github/actions/setup-sccache-dist/action.yml 2>/dev/null || cat .github/actions/setup-sccache-dist/action.yaml
# Confirm whether this step existed prior to this PR (check blame/log for the step).
rg -n "Setup OVH sccache" .github/workflows/live-canary.yml

Repository: nearai/ironclaw

Length of output: 7699


🏁 Script executed:

#!/bin/bash
set -euo pipefail

# Show the relevant workflow region around the checkout and the sccache step.
sed -n '660,760p' .github/workflows/live-canary.yml

# Check whether the repo-local action is invoked after the attacker-controlled checkout.
rg -n "uses: \./\.github/actions/setup-sccache-dist|uses: actions/checkout|target_ref|head_sha|skip_shard" .github/workflows/live-canary.yml

# Inspect whether the composite action itself is modified by this PR or simply reused.
git diff -- .github/actions/setup-sccache-dist/action.yml .github/workflows/live-canary.yml

Repository: nearai/ironclaw

Length of output: 9832


Pin setup-sccache-dist to the canonical harness. In .github/workflows/live-canary.yml:691-752, the canonical checkout only restores scripts/ and tests/e2e; ./.github/actions/setup-sccache-dist still comes from the PR-checked-out tree, so a same-repo target_ref can change the composite action and run it with NEARAI_API_KEY / Slack / OAuth secrets in scope. Same pattern repeats at .github/workflows/live-canary.yml:913-922.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/live-canary.yml around lines 736 - 752, The issue is that
`setup-sccache-dist` is still referenced from the PR checkout, so the workflow
can execute untrusted composite action changes with sensitive secrets in scope.
Update the `Setup OVH sccache` steps in `live-canary.yml` to use the canonical
harness checkout for `setup-sccache-dist`, matching the existing pattern used
for restored `scripts/` and `tests/e2e`, and apply the same fix to the repeated
occurrence later in the workflow. Ensure the action reference is resolved from
the trusted canonical source rather than `./.github/actions/setup-sccache-dist`
in the PR tree.

Source: Path instructions

…eborn-webui-v2-live-qa

The Setup OVH sccache step in prepare-reborn-webui-v2-live-qa runs after a
checkout pinned to steps.target.outputs.checkout_ref, which can be a
validated same-repo PR head SHA. Resolving the secrets-touching
./.github/actions/setup-sccache-dist composite from that ref let a
same-repo branch swap in malicious composite-action code that would run
with SCCACHE_DIST_AUTH_TOKEN and the OVH Redis SSH key in scope.

Add a second checkout pinned to the repository default branch at a
dedicated path and resolve the composite action from there instead,
matching the canonical-checkout idiom already used to restore the
Reborn WebUI v2 live QA harness in the reborn-webui-v2-live-qa job.
@theredspoon
theredspoon force-pushed the codex/upstream-live-canary-cargo-component branch from 9f03fdb to 79158f9 Compare August 4, 2026 22:30
@theredspoon

Copy link
Copy Markdown
Author

Fixed the setup-sccache-dist supply-chain finding from CodeRabbit's 2026-07-04 review (that review's inline comment never posted — GitHub returned "Comments failed to post" for it — so replying here at the PR level instead).

prepare-reborn-webui-v2-live-qa checks out steps.target.outputs.checkout_ref, which can be a validated same-repo PR head SHA (ref: ${{ steps.target.outputs.checkout_ref }}). Its "Setup OVH sccache" step then resolved the secrets-touching ./.github/actions/setup-sccache-dist composite from that same checkout, so a same-repo branch/PR could swap in malicious composite-action code that would run with SCCACHE_DIST_AUTH_TOKEN and the OVH Redis SSH key in scope.

Fixed in 79158f92e by adding a second actions/checkout pinned to ${{ github.event.repository.default_branch }} at a dedicated path (.canonical-live-canary-actions) and resolving the composite action from there instead, matching the canonical-checkout idiom this same workflow already uses to restore the Reborn WebUI v2 live QA harness in the reborn-webui-v2-live-qa job. The canonical checkout is removed again right after the sccache step runs.

New head: 79158f92e.

@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@theredspoon

theredspoon commented Aug 5, 2026 •

Copy link
Copy Markdown
Author

@ilblackdragon, resurfacing this since the original ask is buried in a resolved review thread.

You approved this back on 2026-07-04 (#5101 (comment)), but it was posted as a comment rather than a formal GitHub review, so it never actually registered against branch protection and the PR sat unmerged. It then drifted ~610 commits behind upstream/main over the following month.

Since then: rebased onto current main, plus a new fix (canonical-checkout pinning for setup-sccache-dist in prepare-reborn-webui-v2-live-qa, commit 79158f9). Current head is 31695c6f2.

Could use a fresh review/approval when you get a chance — this time via the actual Review → Approve action so it registers and can enter the merge queue. Branch protection currently shows REVIEW_REQUIRED with no formal approval on record.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

The Remove canonical action checkout step in prepare-reborn-webui-v2-live-qa
lacked always(), so a failed Setup OVH sccache step would skip cleanup of
.canonical-live-canary-actions. Low-impact on ephemeral ubuntu-latest today,
but latent fragility given the workflow also has a persistent self-hosted
runner elsewhere with no build-state cleanup between jobs.
…-canary-cargo-component

# Conflicts:
#	.github/workflows/live-canary.yml
@github-actions github-actions Bot added size: S 10-49 changed lines and removed size: M 50-199 changed lines labels Aug 10, 2026
@coderabbitai

coderabbitai Bot commented Aug 10, 2026

Copy link
Copy Markdown

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/live-canary.yml:
- Around line 812-816: Update the “Remove canonical action checkout” cleanup
step so `.canonical-live-canary-actions` remains available until the referenced
`mozilla-actions/sccache-action` post step and all other job post steps have
completed; move cleanup to a point after those actions finish while preserving
the existing conditional cleanup behavior.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 3ce165b4-cf36-4038-8e1f-b6e5607de479

📥 Commits

Reviewing files that changed from the base of the PR and between 5ba8892 and 4845ffa.

📒 Files selected for processing (2)
  • .github/actionlint.yaml
  • .github/workflows/live-canary.yml

Comment thread .github/workflows/live-canary.yml

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: new First-time contributor risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows size: S 10-49 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants