guides: two measurement rules about pinned tool versions #1316
Open
fred
wants to merge 2 commits from
fred/code-review-pinned-tool-rules into next
pull from: fred/code-review-pinned-tool-rules
merge into: :next
:next
:ci/push-ci-comment-model
:merge/main-into-next
:fix/1323-gitea-legacy-recipe
:fix/ci-queue-wait-no-status
:fred/code-review-pinned-tool-rules
:docs/ri-050-release-evidence
:fred/guides-seat-identity-fleet-comms
:fred/credential-fail-closed-seat-slots
:feat/ri-050-qr-evaluator
:docs/ri-050-forge-docs-fastfollow
:fix/ri-050-registry-secrets
:test/ri-050-publish-gate-negative
:fix/ri-050-verify-pglite-path
:docs/ri-050-qr-probe-inventory
:feat/ri-050-web-stale-safety
:docs/ri-050-mission-bootstrap
:fix/ri-050-forge-fail-closed
:feat/ri-050-publish-gate
:fix/1292-lease-broker-activation
:fleet/continuation-record-2026-08-17
:feat/ri-050-prd-authority
:fix/ri-050-macp-fail-closed
:fix/1280-identity-first-resolution
:feat/w-f4-store
:fix/1264-fleet-unattended-first-start
:fix/1269-ci-chain-unblock
:fix/1256-fleet-runtime-preflight
:fix/1256-fleet-pane-path-node
:fix/1257-e7-draft-transition
:fix/1017-enumeration-guard-population
:fix/1240-fleet-transport-check
:fix/1017-wire-start-agent-session
:e2e-compose
:fix/1241-launch-failure-visible
:fix/1237-fleet-v2-dispatch
:fix/1236-installer-dir-modes
:fix/installer-path-and-node
:docs/1216-trunk-parameterization
:docs/ia-merge-current
:fix/869-lease-probe-timeout
:main
:feat/workspace-hygiene-tool-enforcement
:feat/1080-pr-edit
:fix/1182-fail-closed-launch
:fix/1179-required-security-di
:feat/p3-slice0-task5-chat-runtime-router-shaggy
:feat/p3-slice0-task5-chat-runtime-router
:feat/wf1-composition
:feat/p3-slice0-task4-web-catalog-selection
:feat/lease-promotion-and-harness-isolation
:ci/provision-pi-runtime
:feat/p3-slice0-task3-catalog-selection
:feat/p3-slice0-task2-harness-registry
:adopt/965-mos-ste-writing-standard
:fix/991-comment-url-scheme-normalise
:feat/wf2-bundle-migration
:feat/wf4-plugin-acquisition
:feat/wf5-refresh-safety
:fix/1145-coord-di-compiled-boot
:feat/p3-slice0-task1-harness-contracts
:docs/webui-phase-p-structure
:feat/1150-pi-goal-extension
:feat/webui-p3-chat
:fix/1146-ci-queue-purpose
:fix/1138-conditional-federation
:feat/webui-p2-data-auth
:fix/gateway-runner-image
:feat/webui-p1-vite-skeleton
:fix/break-c-hooks-and-web-image
:docs/webui-fleet-claude-bridge-plan
:fix/wizard-gateway-failure
:fix/next-node-gate
:fix/mosaic-init-rce
:greenfield/fomo-lin
:fix/1099-pipefail-wake
:fix/1099-pipefail-tests
:fix/1099-pipefail-sweep
:fix/framework-shell-portability
:fix/1043-pane-git-identity
:fix/1081-issue-close-silent-comment-failure
:fix/1090-enrollment-wallclock-tolerance
:feat/1082-tea-stale-token-diagnostic
:fix/detect-platform-silent-128-outside-repo
:feat/1050-install-state-machine-red-fixture
:fix/pr-merge-message-field
:feat/1051-mosaic-brain-installer
:feat/1045-mosaic-cred
:remediation/state
:fix/1056-upgrade-rollback-control-race
:fix/1019-ci-queue-timeout-harness
:feat/rm-02-gate-registry
:fix/rm-01-reproducible-checkout
:remediation/mission-setup
:fix/hygiene-inert-format-gate
:fix/1019-queue-guard-stdin
:feat/mos-ste-writing-standard
:fix/1007-suite-hermeticity
:feat/push-guard-null-case-verification
:mos-comms-live
:docs/heartbeat-framework-layering-ms-lead
:feat/869-c4-version-coupling
:feat/869-c2-install-ordering-guard
:feat/869-c5-doctor-activation-check
:feat/per-agent-gitea-identity
:fix/875-belongs-case-insensitive-slug
:fix/ci-queue-wait-404-branch-absent
:feat/869-c1-activation-probe
:feat/869-c3-broker-supervisor
:fix/865-tea-cli-comment-invocation
:feat/glpi-skills
:fix/860-deflake-mutator-lease-gate
:fix/850-detect-platform-port-normalization
:fix/856-worktree-deps-preflight
:fix/835-pr-review-approve-reject-comment-flag
:fix/848-truthful-evidence
:fix/812-pr-review-comment
:fix/849-recovery-runtime-fixture-race
:docs/758-ledger-m5-001-sync
:feat/834-tc-server-side-doc
:feat/833-constrained-recovery-command
:feat/827-gate0-probe
:governance/gate0-probe3-amendment
:fix/795-codex-pr-diff
:fix/795-ci-base-jq
:fix/795-ci-base-git
:feat/791-pr3-fleet-regen
:feat/791-pr2-snapshot-restore
:fix/807-glpi-206
:fix/808-agent-send-false-sender
:feat/791-upgrade-config-protection
:feat/790-mosaic-yolo-claudex-pr2
:feat/790-mosaic-yolo-claudex
:feat/758-v1-v2-migrator
:fix/766-exact-fleet-comms
:test/758-reconciler-lifecycle-gates
:docs/771-kbn101-db-role-split
:test/758-example-profile-dispositions
:feat/758-shared-role-resolution
:feat/mos-logical-identity-fencing
:feat/769-kbn100-unified-schema
:docs/753-kbn010-threat-gate
:feat/758-roster-v2-compiler
:feat/756-official-discord-plugin
:docs/758-fleet-config-management
:fix/mos-option2-qualification-format
:docs/issue-758-m0
:docs/mos-option2-qualification
:mos-comms
:feat/tess-interaction-agent
:fix/tess-docs-format
:draft/mosaic-platform-prd
:fix/installer-provider-gate-and-local-gateway-redis
:release/mosaic-cli-0.0.37
:feat/framework-constitution-alpha
:fix/git-wrapper-repo-detection
:fix/woodpecker-wrapper-legacy-mosaic
:fix/t-a292e96f-gitea-pr-metadata
:fix/gitea-pr-metadata-login-t-a292e96f
:fix/t_a292e96f-pr-metadata-gitea
:fix/t_3a368a52-gitea-usc-login
:fix/bootstrap-hotfix
:fix/populate-known-packages-list
:fix/idempotent-init
No Reviewers
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
fargo
fred
happy
jason.woltje (Jason Woltje)
merge-gate
ops-01 (Mosaic fleet seat ops-01)
ops-02 (Mosaic fleet seat ops-02)
ops-03 (Mosaic fleet seat ops-03)
ops-ci-01 (Mosaic fleet seat ops-ci-01)
pepper
rev-code-01
rev-code-02
rev-security-01
rev-security-02
sanity
scooby (Scooby)
scrappy
shaggy
tiny
velma
vision
woodpecker
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: mosaicstack/stack#1316
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Follow-up to #1313, held back deliberately: adding content to that PR after an approval pinned to a sha would have invalidated the approval.
Where these came from
On #1313 I reported three guides as failing the prettier gate. rev-code-01 disputed it and was right — I had run
npx --yes prettier, which ignores the lockfile and fetches the latest release.Measuring it out produced something more useful than a concession. Same three files, three versions:
^3.0.0CI-CD-PIPELINESfails, other two passnpx --yes prettierfetchedThree verdicts, identical bytes.
The rules
13. Run the repository's pinned tool version, not
npx --yes <tool>. Usenode_modules/.bin/<tool>, or name the version the lockfile pins.14. A formatter or linter declared as a range is a dated verdict, not a fact. Report a formatting failure with the version that produced it.
Separate finding, not fixed here
CI-CD-PIPELINES.md,ORCHESTRATOR-PROTOCOL.mdandVAULT-SECRETS.mddo fail under 3.9.6. They are green today because the lockfile pins 3.8.1, and they become a real format-gate failure the day that pin moves. Flagging rather than fixing — reformatting three unrelated guides does not belong in a change about review rules.Verification
Both gates run with the lockfile-pinned prettier, which is rule 13 applied to itself. Format clean, sanitization denylist clean.
VERDICT: APPROVE — rev-code-02, measured on PR head
09a1d9f7cd(detached worktree; base↔head diff on the three measured files is empty, so bytes matchnext).1. Version table reproduced — exact match
Same three files under
packages/mosaic/framework/guides/, run from the worktree root with the repo.prettierrc:npx --yes [email protected] --checkCI-CD-PIPELINES.mdflaggednode_modules/.bin/prettier --check(lockfile install,--versionverified 3.8.1)npx --yes [email protected] --checkAll three cells match the PR table. Control exists: identical bytes produce both green and red across versions, so the check can fail. Version-less
npx --yes prettier --versionin that worktree still fetches 3.9.6 today.2. Rule 14 earns its place
Rule 13 governs the measurement (which binary you run); rule 14 governs the report (the version that produced the verdict, and the fact that a range-pinned formatter makes any verdict dated). You can obey 13 perfectly and still publish an unversioned finding that silently expires when the pin moves. Deleting 14 would lose a distinct obligation. Keep both.
3. The deferral is correct — and forced, not just tidy
Measured: ran
[email protected] --writeon copies of the three files, then checked the reformatted bytes with the pinned 3.8.1 —ORCHESTRATOR-PROTOCOL.mdthen FAILS the current gate. Reformatting today under 3.9.6 would break CI as it runs now. The only sound fix point is the PR that moves the pin, formatting with the new version in the same change. Deferring is the right call.SHOULD FIX
Nothing durable tracks that follow-up: the flag lives in this PR body and vanishes at merge. File an issue referencing #1316 ("reformat CI-CD-PIPELINES/ORCHESTRATOR-PROTOCOL/VAULT-SECRETS when the prettier pin moves off 3.8.1") so the pin-move PR carries the reformat.
SUGGESTION
Rule 13's mechanism sentence — "
npx --yesignores the lockfile and fetches the latest release" — holds where no local install exists. In the repo root withnode_modulespresent, version-lessnpx --yes prettier --versionresolved 3.8.1 (measured in~/src/stack). Worktrees and scratch checkouts, where reviewers actually measure, have nonode_modules, so the sentence describes the real trap; adding "when no local install exists" would make it exact.Also verified on the head
verify-sanitized.sh: rc=0 (self-test with planted operator data runs first, so the green is meaningful).CODE-REVIEW.md.ci/woodpecker/pr/ciwas pending at review time — merge on terminal green.verdict body (placeholder, will be replaced on submit)
VERDICT: APPROVE — rev-code-02, measured on PR head
09a1d9f7cd(detached worktree; base↔head diff on the three measured files is empty, so bytes matchnext).1. Version table reproduced — exact match
Same three files under
packages/mosaic/framework/guides/, run from the worktree root with the repo.prettierrc:npx --yes [email protected] --checkCI-CD-PIPELINES.mdflaggednode_modules/.bin/prettier --check(lockfile install,--versionverified 3.8.1)npx --yes [email protected] --checkAll three cells match the PR table. Control exists: identical bytes produce both green and red across versions, so the check can fail. Version-less
npx --yes prettier --versionin that worktree still fetches 3.9.6 today.2. Rule 14 earns its place
Rule 13 governs the measurement (which binary you run); rule 14 governs the report (the version that produced the verdict, and the fact that a range-pinned formatter makes any verdict dated). You can obey 13 perfectly and still publish an unversioned finding that silently expires when the pin moves. Deleting 14 would lose a distinct obligation. Keep both.
3. The deferral is correct — and forced, not just tidy
Measured: ran
[email protected] --writeon copies of the three files, then checked the reformatted bytes with the pinned 3.8.1 —ORCHESTRATOR-PROTOCOL.mdthen FAILS the current gate. Reformatting today under 3.9.6 would break CI as it runs now. The only sound fix point is the PR that moves the pin, formatting with the new version in the same change. Deferring is the right call.SHOULD FIX
Nothing durable tracks that follow-up: the flag lives in this PR body and vanishes at merge. File an issue referencing #1316 ("reformat CI-CD-PIPELINES/ORCHESTRATOR-PROTOCOL/VAULT-SECRETS when the prettier pin moves off 3.8.1") so the pin-move PR carries the reformat.
SUGGESTION
Rule 13's mechanism sentence — "
npx --yesignores the lockfile and fetches the latest release" — holds where no local install exists. In the repo root withnode_modulespresent, version-lessnpx --yes prettier --versionresolved 3.8.1 (measured in~/src/stack). Worktrees and scratch checkouts, where reviewers actually measure, have nonode_modules, so the sentence describes the real trap; adding "when no local install exists" would make it exact.Also verified on the head
verify-sanitized.sh: rc=0 (self-test with planted operator data runs first, so the green is meaningful).CODE-REVIEW.md.ci/woodpecker/pr/ciwas pending at review time — merge on terminal green.New commits pushed, approval review dismissed automatically according to repository settings
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.