Add validated bootstrap maintenance workflow - #4
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 384b0be761
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "$REPO_ROOT/scripts/rebuild" build | ||
|
|
||
| echo "Dependencies and release pins were updated; review and commit the diff before switching." | ||
| "$REPO_ROOT/scripts/promote-update" "$baseline" "$candidate" |
There was a problem hiding this comment.
Recheck checkout drift during promotion
If a tracked non-pin file or .local/config.json changes after the comparisons above but while promote-update prepares its recovery journal and replaces the pins, promotion still succeeds because that helper only compares the three pin files. The resulting checkout therefore combines newly promoted pins with source or host selectors that were never built together, while reporting that the candidate passed validation; recheck the complete source and local-config baseline within the promotion transaction and roll back the pins if either drifts.
Useful? React with 👍 / 👎.
Dependency updates previously changed live pins before the full configuration was validated, and Otty handlers were configured during root activation. This change builds updates in a separate candidate checkout, promotes successful candidates with recovery and concurrent-edit checks, and configures handlers in the user's Home Manager session.
It also adds package/Brewfile previews, a read-only doctor, Apple Silicon CI with public system builds and profile-composition checks, and rollback/restore rehearsal documentation. Development and personal tools follow their selected profiles, and Fish shortcuts resolve custom checkout locations. The existing app selection and dependency pins are preserved, including the newer Topgrade Claude Code exclusion from main.
Validation passed locally: the full repository suite, the machine-specific system build, pure public flake checks, and changed/unchanged preview comparisons. Privacy checks passed for tracked/indexed files, reachable history, and the filtered Nix source. Hosted CI will run on this PR; the disposable-Mac activation rehearsal remains manual.