Skip to content

build(rust): pin all product and release lanes to 1.97.1 - #944

Draft
seonghobae wants to merge 89 commits into
bolt-performance-chart-export-13223013812255847379from
agent/rust-toolchain-refresh-2026-08-19
Draft

seonghobae wants to merge 89 commits into
bolt-performance-chart-export-13223013812255847379from
agent/rust-toolchain-refresh-2026-08-19

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 19, 2026 •

Copy link
Copy Markdown
Collaborator

Canonical Rust-toolchain / generic-CI owner

Status: OPEN / Draft / do not merge.

Every source movement invalidates predecessor check/review evidence.

Rust 1.97.1 contract

BandScope pins repository-owned Rust execution to 1.97.1 without widening crate MSRV. Root rust-toolchain.toml, Dependabot update discovery, executable policy verification, ordinary CI, release preflight, dependency audit, and Windows/macOS amd64/arm64 packaging must share that exact reviewed compiler identity. The dedicated verifier rejects floating stable, cross-job evidence borrowing, and failure-masked shell evidence.

Predecessor 407c93773cf0403d3f32e3ddbd77f754b85bae61 repaired release preflight, the consolidated security backstop, four native packaging lanes, and the Rust-contract verifier. 6fb5d8e64351ff63ec9ba23143fdfa012602c68e then fixed the supply-chain verifier's stale cargo +stable audit expectation to cargo +1.97.1 audit; immediate child 10e369ec1e58da1ae6c132e7c33e80f6d6683b81 restored the final newline accidentally removed by the whole-file write.

Fresh exact-source RCA on predecessor 10e369ec...

Hosted repository CI 35942960875 is terminal FAILURE, while build-baseline 35942960738, SAST Semgrep 35942960776, and sbom 35942960729 are terminal SUCCESS. Security and CodeQL were nonterminal when the source moved.

The failed ci / build-and-test job received a runner and checked out exact source 10e369ec1e58da1ae6c132e7c33e80f6d6683b81. Runtime/toolchain setup, numeric extension build, quickcheck, docs/security/supply-chain/bootstrap/Rust policy checks, and ruff check passed. Failure occurred only at ruff format --check src tests, which reported tests/test_supply_chain_policy.py would be reformatted.

That file is not owned by this Rust/toolchain lane. #1176 is the canonical one-file Ruff owner and changes the exact failing assertion from the protected multi-line form to the pinned formatter's one-line form without product/assertion semantics change. Therefore the hosted RED is a valid prerequisite finding, not a Rust 1.97.1 semantic defect.

Non-force prerequisite adoption

Ordinary two-parent descendant db0b7709f48161ca74ff6402ee5f75e136fea40c has parents 10e369ec1e58da1ae6c132e7c33e80f6d6683b81 and #1176 exact 8fe6b6d99c009527ef0bcba419e6f6debdb23c23. Its tree adopts #1176's exact blob 6a085394442846aa68b63ebcd5cfe546747a65b0 for services/analysis-engine/tests/test_supply_chain_policy.py; no formatter implementation was copied or re-authored here.

The branch advanced with a normal fast-forward update and the PR base is retargeted to #1176, so the active #944 diff remains only its 16 Rust/CI-owned paths. Fresh compare from #1176 to db0b770... is ahead-only and contains those 16 paths, with no formatter file.

This is Draft stacking, not acceptance of an unreleased dependency. #1176 must still reach protected ancestry through its central CodeQL/admission prerequisites. After #1176 integrates, this PR must ordinary/non-force reconcile to the new protected develop and reacquire exact-head/base evidence.

Current-head evidence

A fresh workflow generation now exists for exact db0b7709f48161ca74ff6402ee5f75e136fea40c:

  • sbom 35978965029: queued
  • CodeQL PR 35978964008: pending
  • build-baseline 35978963826: queued
  • ci 35978963877: queued
  • SAST Semgrep 35978963867: queued
  • Security Scan 35978963795: queued

No predecessor success transfers to this head. Queued/pending is not GREEN and no current-head independent non-author approval exists.

#944 owns repository Rust-toolchain and generic CI source identity only. It does not own the #1176 formatter delta, product UI, MIR/scientific acceptance, Project Persistence, Resource Admission, Score Storage, Distribution signing/notarization policy, or central .github required-workflow implementation.

Keep Draft until #1176 reaches protected ancestry, this lane is reconciled to protected develop, one unchanged exact head has every applicable build/CI/security/SAST/SBOM/supply-chain/CodeQL gate terminal-success, all valid findings are resolved, and a qualifying independent non-author current-head approval exists.

No self-approval, bypass, synthetic status, source-neutral wake commit, blind rerun, gate weakening, force-push, destructive rebase, duplicate formatter owner, or predecessor-evidence promotion.

@coderabbitai

coderabbitai Bot commented Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Collaborator Author

#1258 adds a new valid ci.yml repair finding that this branch currently overlaps at the file-owner level.

Fresh live evidence from #970 ci run 35704190510 / Ubuntu job 106717643693 shows the protected generic CI checking out refs/remotes/pull/970/merge at synthetic merge commit 2b58ddc6..., not source head 2892a436.... Protected ci.yml has no ref: on any of its three actions/checkout steps, so generic pull-request CI is merge-result evidence by default even where PR authority has called it exact-source evidence.

I am not adding a second concurrent ci.yml writer while #944 still changes that file. #944 is currently Draft and GitHub reports it non-mergeable against its stale base, so the overlap itself is a repair prerequisite: before the next ci.yml source move, ordinary/non-force reconciliation must preserve this PR's valid Rust-toolchain contract and either adopt #1258's exact-source identity contract here or hand ci.yml to a verified successor with complete delta/test/contract succession.

Do not treat the default merge-ref behavior as exact-head GREEN/RED, and do not fix it with a no-op trigger, force-push, destructive rebase, synthetic status, or required-gate weakening.

@seonghobae
seonghobae changed the base branch from develop to bolt-performance-chart-export-13223013812255847379 September 24, 2026 09:04

Copy link
Copy Markdown
Collaborator Author

Fresh exact-head authority on db0b7709f48161ca74ff6402ee5f75e136fea40c:

  • build-baseline 35978963826: SUCCESS. Hosted jobs checked out this exact head, installed Rust 1.97.1, activated the pinned npm runtime, built frontend/native shell, and packaged/uploaded the native artifacts; the observed macOS arm64, Windows arm64, and Windows amd64 lanes are terminal-success in the run inventory.
  • SAST Semgrep 35978963867: SUCCESS.
  • sbom 35978965029, repository ci 35978963877, Security Scan 35978963795, and CodeQL PR 35978964008: still queued/nonterminal at this fresh read.
  • formal current-head reviews: none.

These two successes are genuine evidence for the current two-parent/#1176-stacked head, but they do not make the PR GREEN. Keep Draft; no predecessor-evidence transfer, no blind rerun/no-op wake commit, and no protected reconciliation until #1176 reaches protected ancestry and the remaining exact-head gates settle.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd CI, GitHub Actions, checks, release, or supply chain maintenance priority: medium Normal-priority or P2 work status: draft Draft pull request type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant