Skip to content

R30: reconcile Agent Site installer hardening into CLI v2 - #1530

Merged
vibeforge1111 merged 6 commits into
masterfrom
agent/alchemistab/r30-installer-site-hardening-v2
Jul 28, 2026
Merged

R30: reconcile Agent Site installer hardening into CLI v2#1530
vibeforge1111 merged 6 commits into
masterfrom
agent/alchemistab/r30-installer-site-hardening-v2

Conversation

@vibeforge1111

@vibeforge1111 vibeforge1111 commented Jul 28, 2026

Copy link
Copy Markdown
Owner

Outcome

Reconciles the useful installer hardening already adopted through Spark-Agent-Site PR #185 into the canonical Spark CLI owner lane, without regressing the CLI's newer checksum guidance, broken-Python-alias handling, or copyable PowerShell commands.

This is the immutable successor to spark-cli-public-installer-2026-07-27-r30; the original tag remains unmoved.

Retained contributions

  • bounded uv and Node downloads
  • generated-shell prefix safety
  • uv version and LLM provider validation
  • complete Node (node + npm) and partial-install recovery
  • invalid Git checkout recovery
  • lock acquisition before managed-runtime writes
  • native Windows ARM64/x64 Node selection
  • hosted download + dry-run as the recommended install path

The canonical port preserves the useful intent and attribution of Spark-Agent-Site PR #185 and its source commits while avoiding a wholesale cherry-pick of stale June release metadata.

Release identity

  • release/ref: spark-cli-public-installer-2026-07-27-r30-v2
  • Unix SHA-256: f3dd20a607d6e2ef23b20297e9f74daeac6cd6246b27905cb82aff838b716e64
  • PowerShell SHA-256: 8220ec53bae0a25f7cf67ffb50d3c1ca31ba96cfbcc02b754d313870959b18bc

Proof

  • full suite: 1,461 passed, 2 skipped, 1,158 subtests passed
  • focused installer hardening: 11 passed
  • bash -n scripts/install.sh: passed
  • python3 -m compileall -q src tests: passed
  • R-21 line-count gate: passed, 3 shrinking / 0 growing
  • release-policy binding gate: passed
  • gate/evidence separation: passed
  • local installer manifest integrity: passed
  • binding release gate: permitted

PowerShell parser/runtime proof is deferred to the equipped hosted Windows job.

The binding gate carries one narrow, pre-existing waiver for the historical private Daily Schedule Loop Engineering readiness packet. That capability remains private, blocked, and excluded from R30-v2 publication claims. No installer, security, runtime, source-of-truth, points, or Telegram gate is waived.

Follow-up after merge

  1. publish the new immutable tag at the exact merge commit;
  2. copy these exact installer bytes into Spark Agent Site;
  3. regenerate Site checksums, commands, release manifest, docs, attestations, and signatures;
  4. run hosted Linux/macOS/Windows/Docker proof and hosted-installer verification;
  5. perform final supervised Telegram QA with the single existing poller.

Public team points remain exactly 24,409. Proposed points remain 0.

alchemistab added 5 commits July 28, 2026 21:49
Carry the useful installer protections adopted through Spark-Agent-Site PR #185 into the canonical CLI lane before the R30 successor repin. Preserve bounded downloads, safe generated settings, partial-install recovery, early locking, and native Windows ARM64 Node selection.
Advance the canonical installer release identity without moving the original R30 tag, and bind the manifest to the reconciled Unix and PowerShell bytes.
Preserve Agent Site PR #185's safety flow in the canonical CLI docs and expand enforced coverage across every generated-shell prefix boundary plus both supported Windows Node architectures.
Bind publication-order and hosted-installer gates to the immutable r30-v2 identity while keeping the original R30 tag historical and unmoved.
Update only success-path release manifests that represent the active installer successor; preserve intentional historical and mismatch fixtures.
@cursor

cursor Bot commented Jul 28, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

Fall back to .NET OSArchitecture when PROCESSOR_ARCHITECTURE is absent so cross-host dry-runs retain their safety ordering while real Windows ARM64 and x64 installs select native Node archives.
@vibeforge1111
vibeforge1111 merged commit f254776 into master Jul 28, 2026
8 checks passed
@vibeforge1111
vibeforge1111 deleted the agent/alchemistab/r30-installer-site-hardening-v2 branch July 28, 2026 18:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant