Skip to content

fix(installer): remove commit and pull request prompts - #257

Open
nicknisi wants to merge 6 commits into
mainfrom
riker/14-complete-auth-6733-remove-installer-comm
Open

nicknisi wants to merge 6 commits into
mainfrom
riker/14-complete-auth-6733-remove-installer-comm

Conversation

@nicknisi

Copy link
Copy Markdown
Member

Complete AUTH-6733: remove installer commit-changes and open-PR prompts and automatic commit/push/PR behavior across current CLI, TUI and headless flows, retaining safe compatibility for legacy flags and truthful completion reporting. Adapt existing PR217 to current main and add negative regression tests proving generated changes remain uncommitted.

Riker's check bun run test && bun run typecheck && bun run lint && bun run format:check passed.

Opened as a draft by Riker (job 14).

Adapt scoped removals from d491ef5 by Nick Nisi; preserve today's application setup and branch flow. Replace cwd-based inspection with installDir-scoped, NUL-safe read-only reporting.

Co-authored-by: Nick Nisi <nick.nisi@workos.com>
…aces

Adapt compatibility intent from 8ac52c8; also retain --create-pr, omit legacy defaults, and suppress human notices in JSON. Update current Ink narration instead of the removed dashboard adapter.

Co-authored-by: Nick Nisi <nick.nisi@workos.com>
Drive real parser/orchestration with fake agents, isolated homes/keychains, and fail-on-call model/network/Git publication guards. Cover legacy booleans, human/default/CI/JSON paths, hosted Ink completion, branch policy, cancellation/failure, and truthful installDir inspection. Include inspection state in headless completion and disable optional Git index locks.
The extraction race specs deleted the version/UID-keyed temp cache used by parallel doctor --fix tests. A deletion between materialization and discoverSkills made real refreshWorkOSSkills return null, failing the sibling-protection assertion.

Reproduced the exact null failure with a filesystem scheduling barrier in isolated archives of base 2f19926 and AUTH-6733 d8f5a4e (3/3 each). The same barrier passes 3/3 with this fixture isolation; an unchanged baseline still fails. Ordinary paired runs passed 12/12 each, confirming the timing sensitivity rather than relying on a retry until green.

Mock only this spec's tmpdir to a unique directory, clean it afterward, and assert it differs from the real shared temp directory. Keep real materialization, allowlist and sibling-write protection assertions unchanged. No production or installer branch behavior changes.
@linear-code

linear-code Bot commented Sep 28, 2026

Copy link
Copy Markdown

AUTH-6733

@nicknisi nicknisi changed the title Complete AUTH-6733: remove installer commit-changes and open-PR prompts… fix(installer): remove commit and pull request prompts Sep 28, 2026
@nicknisi
nicknisi marked this pull request as ready for review September 28, 2026 20:09
@greptile-apps

greptile-apps Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium risk] Removes commit and pull request automation from the installer.

The PR appears safe to merge based on the reviewed changes.

Summary

The PR removes installer-controlled commits, pushes, and pull requests while retaining legacy flags as no-ops.

  • Completion now reports Git inspection outcomes and tells users to review and commit changes themselves.
  • New tests cover the parser, installer flows, staged-work preservation, and bounded inspection.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Installer succeeds] --> B[Inspect install directory]
  B --> C{Inspection outcome}
  C -->|Changed| D[Report current changed files]
  C -->|Unchanged| E[Report no Git changes]
  C -->|Unavailable| F[Report files unknown]
  D --> G[Complete without staging or publishing]
  E --> G
  F --> G
Loading

Reviews (2) · Last reviewed commit: "fix: bound post-install Git change inspe..."

Comment thread src/bin-readonly-installer.integration.spec.ts Outdated
Comment thread src/lib/post-install.ts
Replace import-time which and POSIX executable shims with Bun process interception before CLI imports. Only inspection and branch creation reach real Git; probes assert all forbidden process APIs record failures even if caught. Use isolated empty Git config files and preserve Windows subprocess environment paths. Exercise POSIX-only filename characters through NUL output fixtures on every platform instead of creating invalid Windows filenames.
Limit each inspection command to five seconds and one MiB, force termination on timeout, and report explicit unknown-file errors on timeout/overflow without consuming partial output. Preserve NUL-safe filenames, rename handling, optional-lock suppression, branch policy, and successful installation evidence independently of inspection.

Cover large complete listings, both command phases, null stderr, and real Bun subprocess timeout/overflow through offline orchestration with unchanged HEAD/index checks. Document inspection limits.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant