Repository navigation
chore(policy): forbid compiling a third-party tool from source (CLOUD-86) - #225
Merged
wenzowski merged 1 commit intoAug 10, 2026
Conversation
CLOUD-86 Add prebuilt-lint for compiled artifacts the repo did not build
Why Acceptance
Refinement — Ready (forbid rules over build config catch compile-from-source; exemptions wait on the waiver surface) Refinement gate: Definition of Ready & Done. This body carries only specializations.
Stated assumptions (flagged rather than blocking)
|
CLOUD-86. Two `[[rule]]` rows in this repository's own batten.toml, as consumer #1 — no engine change. A tool built here is a tool nobody attested: the build runs on whatever toolchain the runner had and produces a binary no checksum covers, while every tool this repo uses is pinned in mise.toml as a prebuilt artifact with a locked url and a per-platform checksum. CLOUD-281 is the instance where the one tool not pinned that way was the one installed from an unverified download. Two rows because a `forbid` pattern is a literal substring and the two files spell the same mistake differently: `"cargo:` in mise.toml (the opening quote is load-bearing — TOML bare keys cannot contain `:`, so a backend key is always quoted, which keeps the row off prose that merely says "cargo"), and `cargo install` in a workflow. The exemption half is what this waited on CLOUD-208 for: an exemption is a `[[waiver]]` carrying a reason and an expiry, never `severity = "allow"`, which records no reason and lapses never. The suite covers the whole shape — a waived entry passes, a lapsed one is red again with nobody having acted, an exemption with no reason is exit 1 rather than applied, and a second violation still blocks. release-artifacts.yml's CLOUD-259 comment narrated install-action's fallback chain ending in the literal command, so it was the one hit on a clean tree. Reworded, because a gate that fires on its own explanation is a gate people delete. Narrowing the pattern to `run: cargo install` was the alternative and would have missed the block form — coverage that looks total and isn't. Not gated here: whether a PREBUILT artifact is attested. That is CLOUD-90's manifest and CLOUD-281's `github:`-vs-`ubi:` distinction; a row firing on `ubi:` would be answering a different question.
wenzowski
marked this pull request as ready for review
August 10, 2026 20:33
wenzowski
force-pushed
the
wenzowski/cloud-86-add-prebuilt-lint-for-compiled-artifacts-the-repo-did-not
branch
from
August 10, 2026 20:33
4aee6b7 to
4a94f05
Compare
Contributor
Author
|
/fast-forward |
wenzowski
deleted the
wenzowski/cloud-86-add-prebuilt-lint-for-compiled-artifacts-the-repo-did-not
branch
August 10, 2026 20:38
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes CLOUD-86. Config-only — two
[[rule]]rows in this repository's ownbatten.tomlas consumer #1, plus their bats suite. No crate change.The property
A tool built here is a tool nobody attested: the build runs on whatever toolchain
the runner had and produces a binary no checksum covers. Every tool this repo uses
is pinned in
mise.tomlas a prebuilt artifact with a locked url and aper-platform checksum — CLOUD-281 is the instance where the one tool not pinned
that way was the one installed from an unverified download.
Two rows, because a
forbidpattern is a literal substring and the two filesspell the same mistake differently:
no-source-built-toolmise.toml"cargo:no-cargo-install-in-ci.github/workflows/*.ymlcargo installThe opening quote in the first is load-bearing: TOML bare keys cannot contain
:, so a backend key is always quoted, and the quote is what keeps the row offprose that merely says "cargo".
The exemption half is why this was blocked on CLOUD-208
An exemption is a
[[waiver]]carrying a reason and an expiry — neverseverity = "allow", which records no reason and lapses never. That is acceptancecase (c), and the suite covers the whole shape rather than only the happy path: a
waived entry passes with a pointer-only audit line on stderr, a lapsed one is
red again with nobody having acted, an exemption with an empty
reasonis exit1(bad input, not a verdict), and a second un-waived violation still blocks.One reworded comment, stated rather than quietly narrowed
release-artifacts.ymlexplains CLOUD-259 by narrating install-action's fallbackchain, which ended in the literal
cargo install— the single hit on a cleantree. The comment now says "a from-source crate build" and says why. Narrowing the
pattern to
run: cargo installwas the alternative and was rejected: it wouldhave missed the block form (
run: |with the command on its own line), which iscoverage that looks total and isn't. A gate that fires on its own documentation is
a gate people delete.
Not gated here
Whether a prebuilt artifact is attested. That is CLOUD-90's
[[provision]]manifest and CLOUD-281's
github:-vs-ubi:distinction; a row firing onubi:would be answering a different question. The issue's stated assumption 1 held up.
Amendment to the Ready block
§5 said a violation exits
1. It exits2— the policy verdict, on every surfacethat renders one. Measured, asserted, and recorded on the issue.
Verification
mise run fmt(hk fix --all, ending inbatten-checkover these very rows)green, and all 9 cases of
tests/prebuilt-lint.batspass.Generated by Claude Code