Repository navigation
fix: complete the Homebrew formula handoff - #58
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 14, 2026, 11:34 AM ET / 15:34 UTC (Revision 2). ClawSweeper reviewWhat this changesSwitch Homebrew installation guidance to the Formula, update the trusted tap revision, accept URL-derived versions and provenance-only commits, and document release recovery. Merge readiness✅ Ready for maintainer review The prior updater incompatibility is resolved by the corrected, merged tap pin. No remaining introduced defect was found; this PR remains necessary because current main still uses the blocked handoff contract. Priority: P2 Review scores
Verification
How this fits togetherThe release producer verifies published goplaces binaries and passes their hashes to the Homebrew tap updater. It then checks the resulting Formula commit and installed binary before recording completion. flowchart TD
A[Published release assets] --> B[Verify identities and hashes]
B --> C[Check pinned tap contract]
C --> D[Dispatch Formula updater]
D --> E[Validate commit and Formula]
E --> F[Verify installed binary]
F --> G[Record release completion]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Use the corrected Formula contract while preserving exact release identities, serialized dispatch, and installed-binary verification. Do we have a high-confidence way to reproduce the issue? Yes, from source: current main pins the blocked tap contract and rejects the Formula's absent explicit version. No release operation was executed during this review. Is this the best way to solve the issue? Yes. The corrected tap pin and narrow validator changes reconcile the existing producer with the merged Formula contract without adding a competing release path. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against 727965013a90. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (1 earlier review cycle)
|
Install goplaces through
brew install openclaw/tap/goplacesinstead of the retired Cask. Update the README, website, migration instructions, and Unreleased changelog, and pin tap commit104616d9828cf28202bccff19c0738f179c2a3f8from openclaw/homebrew-tap#56 and openclaw/homebrew-tap#57.The handoff accepts URL-derived versions and one direct-child provenance-only commit for an already-current Formula. Ruby tokenization rejects noncanonical or duplicate version declarations without evaluating the Formula. Exact release URLs, all four hashes, commit parent, provenance trailers, and unrelated-file rejection remain enforced. GoReleaser already contains no Cask generator; its guard remains in place.
Document the equivalent recovery handoff for published v0.4.11 after release closeout advanced main. It preserves the original frozen records and native release proofs, separately pins current protected source main, verifies unchanged verifier policy and two independent asset copies, then binds one exact tap workflow run, commit, and installed binary. This does not rebuild, republish, or move the release tag.
Validation: independent P0–P2 review returned scoped-clean for the implementation and final pin. The full local release-contract suite, focused Formula/version/provenance regressions, ShellCheck, documentation metadata tests, and final CI passed: https://github.com/openclaw/goplaces/actions/runs/34862450343. The tap's strict online audit, branch install, package test, exact binary equality, Developer ID requirements, and online notarization checks passed for 0.4.11; its final shared-updater tests and macOS ARM64/Intel/Linux install checks also passed.