fix: pin the marker-restored Homebrew updater - #59
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 14, 2026, 11:53 AM ET / 15:53 UTC. ClawSweeper reviewWhat this changesUpdates the Homebrew release updater’s trusted commit to the marker-restored revision and synchronizes its documentation and test fixtures. Merge readiness✅ Ready for maintainer review This correction remains necessary: current main still pins the marker-less updater. The replacement is a verified merged tap commit with no executable changes, and no introduced correctness or security defect was found. Priority: P2 Review scores
Verification
How this fits togetherThe release script hands verified goplaces archives to the Homebrew tap’s updater. It checks the pinned source before dispatch, then verifies the resulting package commit and installed binary. flowchart TD
A[Verified release archives] --> B[Release handoff]
C[Pinned tap commit] --> D[Check protected branch and updater]
B --> D
D --> E[Dispatch exact workflow]
E --> F[Verify package commit]
F --> G[Verify installed binary]
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Technical reviewBest possible solution: Use the reviewed marker-restored tap revision while preserving exact source, dispatch, recovery, and installed-binary verification. Do we have a high-confidence way to reproduce the issue? Yes, from source: main pins an updater without the exact marker its preflight requires, and the live protected tap head has also advanced beyond that pin. No release workflow was executed in this review. Is this the best way to solve the issue? Yes. Re-pinning to the verified comment-only restoration is the narrow repair and preserves the existing fail-closed checks. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against 4647985cfba9. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
Pin the Homebrew trust anchor to
c697e7ce1bf42f8c4a8c909e117204f3beadd088, the reviewed marker-restoration merge from openclaw/homebrew-tap#58. The live v0.4.11 preflight correctly rejected the previous base because an earlier tap refactor had removed the exact# verified-hashes-v1marker.Update the production pin, matching contract fixtures, and playbook together. Verification logic stays unchanged. The tap restoration changes no executable behavior, passed all 78 updater/workflow tests and independent review, and restores the marker rather than relaxing the source trust check. No handoff dispatch occurred before this correction.
Independent P0–P2 review of this pin update returned scoped-clean. The implementation from #58 has already passed full local release-contract tests and green CI; this follow-up also passed full CI: https://github.com/openclaw/goplaces/actions/runs/34864531218. The one-time handoff follows this merge.