Skip to content

fix: pin the marker-restored Homebrew updater - #59

Merged
steipete merged 1 commit into
mainfrom
fix/homebrew-marker-pin
Sep 14, 2026
Merged

steipete merged 1 commit into
mainfrom
fix/homebrew-marker-pin

Conversation

@steipete

@steipete steipete commented Sep 14, 2026 •

Copy link
Copy Markdown
Collaborator

Pin the Homebrew trust anchor to c697e7ce1bf42f8c4a8c909e117204f3beadd088, the reviewed marker-restoration merge from openclaw/homebrew-tap#58. The live v0.4.11 preflight correctly rejected the previous base because an earlier tap refactor had removed the exact # verified-hashes-v1 marker.

Update the production pin, matching contract fixtures, and playbook together. Verification logic stays unchanged. The tap restoration changes no executable behavior, passed all 78 updater/workflow tests and independent review, and restores the marker rather than relaxing the source trust check. No handoff dispatch occurred before this correction.

Independent P0–P2 review of this pin update returned scoped-clean. The implementation from #58 has already passed full local release-contract tests and green CI; this follow-up also passed full CI: https://github.com/openclaw/goplaces/actions/runs/34864531218. The one-time handoff follows this merge.

@steipete
steipete requested a review from a team as a code owner September 14, 2026 15:47
@clawsweeper

clawsweeper Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 14, 2026
@clawsweeper

clawsweeper Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge. Reviewed September 14, 2026, 11:53 AM ET / 15:53 UTC.

ClawSweeper review

What this changes

Updates the Homebrew release updater’s trusted commit to the marker-restored revision and synchronizes its documentation and test fixtures.

Merge readiness

✅ Ready for maintainer review

This correction remains necessary: current main still pins the marker-less updater. The replacement is a verified merged tap commit with no executable changes, and no introduced correctness or security defect was found.

Priority: P2
Reviewed head: 86785cf518d4dbcb9e093204f0a967523a033e11

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused, consistent pin correction with independently verified dependency changes and no actionable findings.
Proof confidence 🌊 off-meta tidepool Not applicable: The collaborator-authored pin correction is exempt from ordinary contributor proof. The body reports the real preflight failure, but does not demonstrate an after-fix handoff; the inspected dependency delta and unchanged authority checks establish no additional authority-proof requirement.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The collaborator-authored pin correction is exempt from ordinary contributor proof. The body reports the real preflight failure, but does not demonstrate an after-fix handoff; the inspected dependency delta and unchanged authority checks establish no additional authority-proof requirement.
Evidence reviewed 7 items Introduced change: The complete pinned-base-to-head diff changes one production constant, ten fixture lines, and two documentation lines; verification logic is unchanged.
Still needed on main: GitHub still reports main at 4647985. That revision pins 104616d9828cf28202bccff19c0738f179c2a3f8; the latest release v0.4.11 has an older pin, 45b93a0b3de27e46b636a0cef819fb1ecef25bcd.
Explicit dependency and trust boundary: The preflight reads openclaw/homebrew-tap workflow and updater contents at TAP_BASE, requires protected main to equal that pin, and rejects a missing exact marker. Dispatch repeats the trust check; persisted requests remain bound to the pin and exact workflow identity.
Findings None None.
Security None None.

How this fits together

The release script hands verified goplaces archives to the Homebrew tap’s updater. It checks the pinned source before dispatch, then verifies the resulting package commit and installed binary.

flowchart TD
  A[Verified release archives] --> B[Release handoff]
  C[Pinned tap commit] --> D[Check protected branch and updater]
  B --> D
  D --> E[Dispatch exact workflow]
  E --> F[Verify package commit]
  F --> G[Verify installed binary]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Use the reviewed marker-restored tap revision while preserving exact source, dispatch, recovery, and installed-binary verification.

Do we have a high-confidence way to reproduce the issue?

Yes, from source: main pins an updater without the exact marker its preflight requires, and the live protected tap head has also advanced beyond that pin. No release workflow was executed in this review.

Is this the best way to solve the issue?

Yes. Re-pinning to the verified comment-only restoration is the narrow repair and preserves the existing fail-closed checks.

AGENTS.md: not found in the target repository.

Codex review notes: model internal, reasoning medium; reviewed against 4647985cfba9.

Labels

Label changes:

  • add P2: Repairs a bounded release-operator Homebrew handoff failure without changing the installed application.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The collaborator-authored pin correction is exempt from ordinary contributor proof. The body reports the real preflight failure, but does not demonstrate an after-fix handoff; the inspected dependency delta and unchanged authority checks establish no additional authority-proof requirement.

Label justifications:

  • P2: Repairs a bounded release-operator Homebrew handoff failure without changing the installed application.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The collaborator-authored pin correction is exempt from ordinary contributor proof. The body reports the real preflight failure, but does not demonstrate an after-fix handoff; the inspected dependency delta and unchanged authority checks establish no additional authority-proof requirement.

Evidence

What I checked:

  • Introduced change: The complete pinned-base-to-head diff changes one production constant, ten fixture lines, and two documentation lines; verification logic is unchanged. (scripts/release-local:16, 86785cf518d4)
  • Still needed on main: GitHub still reports main at 4647985. That revision pins 104616d9828cf28202bccff19c0738f179c2a3f8; the latest release v0.4.11 has an older pin, 45b93a0b3de27e46b636a0cef819fb1ecef25bcd. (scripts/release-local:16, 4647985cfba9)
  • Explicit dependency and trust boundary: The preflight reads openclaw/homebrew-tap workflow and updater contents at TAP_BASE, requires protected main to equal that pin, and rejects a missing exact marker. Dispatch repeats the trust check; persisted requests remain bound to the pin and exact workflow identity. (scripts/release-local:2410, 86785cf518d4)
  • Verified dependency delta: The old-to-new comparison contains exactly one commit and three changed files: a standalone marker comment in the updater, a marker regression test, and changelog prose. Workflow, parser helper, and executable updater behavior are unchanged. (.github/scripts/update_formula.py:209, c697e7ce1bf4)
  • Merged restoration and live anchor: GitHub confirms fix: restore the verified handoff trust marker homebrew-tap#58 merged as c697e7ce1bf42f8c4a8c909e117204f3beadd088. Its body records the pre-dispatch rejection and 78 passing tests; a separate branch read confirms protected main currently equals that commit. (c697e7ce1bf4)
  • Prior implementation and routing history: The bounded release-script history repeatedly identifies Peter Steinberger. GitHub maps the immediately preceding Formula handoff commit to steipete and confirms its added version-validation helper. Deeper local history reads encountered unavailable objects; GitHub commit metadata and patches supplied the relevant prior-change evidence. (scripts/release-local:2774, 4647985cfba9)

Likely related people:

  • unknown: The claimed source-line change could not be verified from bounded local history. (role: source history unknown; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@steipete
steipete merged commit f408ca1 into main Sep 14, 2026
12 checks passed
@steipete
steipete deleted the fix/homebrew-marker-pin branch September 14, 2026 15:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant