R30: reconcile Agent Site installer hardening into CLI v2 - #1530
Merged
vibeforge1111 merged 6 commits intoJul 28, 2026
Conversation
added 5 commits
July 28, 2026 21:49
Carry the useful installer protections adopted through Spark-Agent-Site PR #185 into the canonical CLI lane before the R30 successor repin. Preserve bounded downloads, safe generated settings, partial-install recovery, early locking, and native Windows ARM64 Node selection.
Advance the canonical installer release identity without moving the original R30 tag, and bind the manifest to the reconciled Unix and PowerShell bytes.
Preserve Agent Site PR #185's safety flow in the canonical CLI docs and expand enforced coverage across every generated-shell prefix boundary plus both supported Windows Node architectures.
Bind publication-order and hosted-installer gates to the immutable r30-v2 identity while keeping the original R30 tag historical and unmoved.
Update only success-path release manifests that represent the active installer successor; preserve intentional historical and mismatch fixtures.
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
Fall back to .NET OSArchitecture when PROCESSOR_ARCHITECTURE is absent so cross-host dry-runs retain their safety ordering while real Windows ARM64 and x64 installs select native Node archives.
vibeforge1111
deleted the
agent/alchemistab/r30-installer-site-hardening-v2
branch
July 28, 2026 18:07
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Reconciles the useful installer hardening already adopted through Spark-Agent-Site PR #185 into the canonical Spark CLI owner lane, without regressing the CLI's newer checksum guidance, broken-Python-alias handling, or copyable PowerShell commands.
This is the immutable successor to
spark-cli-public-installer-2026-07-27-r30; the original tag remains unmoved.Retained contributions
node+npm) and partial-install recoveryThe canonical port preserves the useful intent and attribution of Spark-Agent-Site PR #185 and its source commits while avoiding a wholesale cherry-pick of stale June release metadata.
Release identity
spark-cli-public-installer-2026-07-27-r30-v2f3dd20a607d6e2ef23b20297e9f74daeac6cd6246b27905cb82aff838b716e648220ec53bae0a25f7cf67ffb50d3c1ca31ba96cfbcc02b754d313870959b18bcProof
bash -n scripts/install.sh: passedpython3 -m compileall -q src tests: passedPowerShell parser/runtime proof is deferred to the equipped hosted Windows job.
The binding gate carries one narrow, pre-existing waiver for the historical private Daily Schedule Loop Engineering readiness packet. That capability remains private, blocked, and excluded from R30-v2 publication claims. No installer, security, runtime, source-of-truth, points, or Telegram gate is waived.
Follow-up after merge
Public team points remain exactly 24,409. Proposed points remain 0.