Skip to content

Add portable Dev Box bootstrap with Linuxbrew WSL setup - #13

Merged
vcfvct merged 1 commit into
masterfrom
feat/devbox-linuxbrew-bootstrap
Sep 14, 2026
Merged

vcfvct merged 1 commit into
masterfrom
feat/devbox-linuxbrew-bootstrap

Conversation

@vcfvct

@vcfvct vcfvct commented Sep 14, 2026

Copy link
Copy Markdown
Owner

Add Dev Box YAML, phased Windows and Ubuntu provisioning, safe dotfile installation, documentation, and regression tests. Use Linuxbrew for Ubuntu developer tools and reserve apt for OS prerequisites.

Add Dev Box YAML, phased Windows and Ubuntu provisioning, safe dotfile installation, documentation, and regression tests. Use Linuxbrew for Ubuntu developer tools and reserve apt for OS prerequisites.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2c36dd7a-f505-40bd-8ea0-eded9e24c479

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved critical and moderate findings remain in provisioning security, workload pinning, settings propagation, and linker safety.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds a portable Windows and Ubuntu WSL2 Dev Box bootstrap using phased provisioning, Linuxbrew tooling, safe dotfile management, documentation, and regression tests.

Changes:

  • Adds Windows, WSL, and Ubuntu provisioning workflows.
  • Adds Linuxbrew, Fish setup, package definitions, and verification.
  • Adds linker safety features, tests, and documentation.
File summaries
File Summary
wsl/powershell_profile.ps1 Corrects fnm PowerShell initialization.
workload.yaml Adds the Dev Box customization entry point.
symbolLink.js Provides safe linking, backups, planning, and verification.
README.md Links to Dev Box setup documentation.
devbox/tests/validate.ps1 Adds PowerShell and shell validation tests.
devbox/tests/linker.test.cjs Adds linker regression tests.
devbox/settings.json Defines provisioning settings and packages.
devbox/scripts/wsl-user.ps1 Provisions the configured WSL environment.
devbox/scripts/wsl-platform.ps1 Enables WSL platform prerequisites.
devbox/scripts/windows.ps1 Installs Windows tools and configuration.
devbox/scripts/verify.ps1 Verifies Windows and WSL setup.
devbox/scripts/ubuntu-verify.sh Verifies Linuxbrew tools and links.
devbox/scripts/ubuntu-root.sh Performs privileged Ubuntu setup.
devbox/scripts/ubuntu-bootstrap.sh Performs user-level Linuxbrew bootstrap.
devbox/scripts/fish-plugins.fish Installs configured Fish plugins.
devbox/scripts/common.ps1 Provides shared PowerShell helpers.
devbox/README.md Documents setup and safety behavior.
devbox/Brewfile Defines Linuxbrew developer packages.
devbox/bootstrap.ps1 Orchestrates provisioning phases.
devbox/.gitattributes Enforces Unix line endings for Linux scripts.
Review details

Suppressed comments (4)

devbox/scripts/ubuntu-bootstrap.sh:58

  • The safe linker checks linked parents for its manifest, but this later write does not check $HOME/.config/fish/conf.d. If that directory already links elsewhere, mkdir/mv writes devbox-brew.fish into the linked target, violating the bootstrap's safety guarantee. Reject or safely handle linked parents before creating this managed file.
mkdir -p "$HOME/.config/fish/conf.d"

devbox/scripts/windows.ps1:9

  • --source winget restricts detection to packages installed from that source. An existing package installed from Microsoft Store or another source is therefore treated as missing, and the subsequent install can fail or attempt a second installation, contrary to the no-upgrade/idempotent behavior. Detect by exact ID without the source filter while retaining the source restriction on install.
    & winget.exe list --id $id --exact --source winget --accept-source-agreements --disable-interactivity | Out-Host

symbolLink.js:150

  • Windows file entries use mode === 'copy', but this early return accepts a matching source symlink for every mode. A legacy link is consequently left in place instead of being converted to a copy, so source edits still propagate and the documented Windows copy isolation is bypassed. Only treat matching symlinks as no-ops for link mode.
    if (existing?.isSymbolicLink()) {
      const target = path.resolve(path.dirname(destination), await fs.readlink(destination));
      if (target === source) return;

symbolLink.js:117

  • Copy verification reads the destination through symlinks. A manually or legacy-symlinked Windows target that points to the source therefore passes --verify as a valid copy even though it violates copy mode. Check the destination with lstat and require a regular file before comparing bytes.
        if (entry.mode === 'copy') {
          if (!(await fs.readFile(entry.source)).equals(await fs.readFile(entry.destination))) {
  • Files reviewed: 20/20 changed files
  • Comments generated: 4
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

grep -Fxq "$fish" /etc/shells || printf '%s\n' "$fish" >> /etc/shells
[[ $(getent passwd "$user" | cut -d: -f7) == "$fish" ]] || usermod --shell "$fish" "$user"
# Preserve other WSL settings; update only the default user in its INI section.
/home/linuxbrew/.linuxbrew/bin/python3 - "$user" <<'PY'
Comment thread workload.yaml
Comment thread workload.yaml
Comment on lines +24 to +28
$bootstrap = Join-Path $repo 'devbox\bootstrap.ps1'
if (-not (Test-Path -LiteralPath $bootstrap)) {
throw 'Bootstrap files are not published or the existing checkout is outdated. Update it explicitly, preserving local changes.'
}
pwsh -NoLogo -NoProfile -File $bootstrap -Phase All
Comment thread devbox/settings.json
"distro": "Ubuntu-24.04",
"linuxUser": "",
"homebrewInstallerRevision": "8949852f785a3bacaba2a979d0790337950b0a4a",
"nodeVersion": "22",
@vcfvct
vcfvct merged commit 39416ec into master Sep 14, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants