build(rust): pin all product and release lanes to 1.97.1 - #944
build(rust): pin all product and release lanes to 1.97.1#944seonghobae wants to merge 58 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent Repair the exact current-head Ruff I001 on the existing |
|
@opencode-agent Repair the exact current-head BandScope-owned quickcheck failure on the existing |
|
@opencode-agent repair Fresh 2026-08-25 refetch still shows the canonical branch Update only the stale occurrences inside these seven tests:
There are 11 stale Then run the focused |
|
@opencode-agent repair Fresh writer-lease refetch: PR #944 is still exactly Current exact RED remains CI run
Change only the 11 Verification-before-completion: run the focused |
|
@OpenCode Use This exact head still has the BandScope-owned deterministic quickcheck defect already proven by CI run Repair only the stale test contract in the seven known scopes: replace only their obsolete Rust-audit fixture/expected-violation occurrences with |
Problem
BandScope's Rust-backed analysis build, Tauri validation, release preflight, dependency audit, and native packaging lanes must use one reviewed compiler and must not be able to manufacture compiler/test evidence from non-executing or failure-masked shell text.
Rust
1.97.1is the reviewed repository build baseline. Floatingstableselection can change scientific, security, and release evidence without a repository diff.Exact current identity
develop@acdbea6344fe1231c39535b575f4de35e4c607c9.b0f8cf0de9f02ee1bed7a8ee964daed6d2063562.agent/rust-toolchain-refresh-2026-08-19.Current contract
rust-toolchain.tomlpins Rust1.97.1;rust-toolchainupdate discovery targets protecteddevelop;scripts/checks/verify_rust_toolchain.pyrejects floating selectors and evidence borrowed across Dependabot lanes, workflow files, sibling jobs, comments, step names, environment text, or other non-executing YAML;--manifest-path,--locked, or explicit target triples, but may not use shell chaining/pipelines/background control operators that can replace the required command's exit status; andTest-first hardening
Earlier TDD on this branch closed cross-Dependabot-lane, comment-only field, cross-workflow, cross-native-job, non-executable-
run, failure-masked shell, and workflow evidence-authority gaps. Those repairs are retained on the current branch.The exact current CI now exposes a narrower test-contract drift rather than a production verifier defect.
Exact-current-head verification
Current exact CI evidence binds to head
b0f8cf0de9f02ee1bed7a8ee964daed6d2063562:32597173161;ci / build-and-testjob97089876119;bc81a8797006b797b71cbe258dd8e27aef40a062against protecteddevelop@acdbea6344fe1231c39535b575f4de35e4c607c9.That job proves:
services/analysis-engine/tests/test_supply_chain_policy.pybecause those fixtures/assertions still encode obsoletecargo +stable audittext while the canonical production verifier/workflow requirescargo +1.97.1 audit.The stale contract is limited to these seven tests:
test_security_audit_workflow_keeps_dependency_vulnerability_scans,test_supply_chain_check_requires_audit_tokens_in_run_steps,test_supply_chain_check_accepts_nested_shell_audit_commands,test_supply_chain_check_rejects_noop_audit_command_spoofs,test_supply_chain_check_requires_blocking_audit_steps,test_supply_chain_check_requires_unconditional_audit_steps, andtest_supply_chain_check_accepts_explicit_false_continue_on_error_audit_steps.A fresh same-head owner-control repair request is attached to the existing PR conversation. It instructs the canonical branch writer to update only the 11 stale
cargo +stable auditoccurrences inside those seven test scopes tocargo +1.97.1 audit, preserve intentional floating-selector rejection cases elsewhere, keepverify_supply_chain.pyunchanged, and rerun the focused file, repository-pinned Ruff check/format, and canonical quickcheck. Until a successor exact head exists and is reverified, this PR remains RED/non-ready.Protected-base JavaScript dependency/security remediation remains canonical #783-owned. Do not copy or suppress that authority in this Rust-toolchain lane.
Merge gate
Keep Draft and unmerged until one unchanged resulting exact head has every applicable repository and central CI/build/release/security/SAST/SBOM/supply-chain/coverage/review gate terminal-success, the Rust toolchain policy tests pass through canonical quickcheck, inherited dependency security is resolved by #783 rather than suppressed here, zero valid unresolved findings remain, a qualifying independent non-author last-push approval exists, and ordinary protected-branch rules permit merge without bypass. Queued, pending, skipped-required, failed, stale, predecessor-head, protected-base, model-only, self/author, or administrative-bypass evidence is non-passing.