Add portable Dev Box bootstrap with Linuxbrew WSL setup - #13
Merged
Merged
Conversation
Add Dev Box YAML, phased Windows and Ubuntu provisioning, safe dotfile installation, documentation, and regression tests. Use Linuxbrew for Ubuntu developer tools and reserve apt for OS prerequisites. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 2c36dd7a-f505-40bd-8ea0-eded9e24c479
There was a problem hiding this comment.
🟡 Changes recommended
Unresolved critical and moderate findings remain in provisioning security, workload pinning, settings propagation, and linker safety.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds a portable Windows and Ubuntu WSL2 Dev Box bootstrap using phased provisioning, Linuxbrew tooling, safe dotfile management, documentation, and regression tests.
Changes:
- Adds Windows, WSL, and Ubuntu provisioning workflows.
- Adds Linuxbrew, Fish setup, package definitions, and verification.
- Adds linker safety features, tests, and documentation.
File summaries
| File | Summary |
|---|---|
wsl/powershell_profile.ps1 |
Corrects fnm PowerShell initialization. |
workload.yaml |
Adds the Dev Box customization entry point. |
symbolLink.js |
Provides safe linking, backups, planning, and verification. |
README.md |
Links to Dev Box setup documentation. |
devbox/tests/validate.ps1 |
Adds PowerShell and shell validation tests. |
devbox/tests/linker.test.cjs |
Adds linker regression tests. |
devbox/settings.json |
Defines provisioning settings and packages. |
devbox/scripts/wsl-user.ps1 |
Provisions the configured WSL environment. |
devbox/scripts/wsl-platform.ps1 |
Enables WSL platform prerequisites. |
devbox/scripts/windows.ps1 |
Installs Windows tools and configuration. |
devbox/scripts/verify.ps1 |
Verifies Windows and WSL setup. |
devbox/scripts/ubuntu-verify.sh |
Verifies Linuxbrew tools and links. |
devbox/scripts/ubuntu-root.sh |
Performs privileged Ubuntu setup. |
devbox/scripts/ubuntu-bootstrap.sh |
Performs user-level Linuxbrew bootstrap. |
devbox/scripts/fish-plugins.fish |
Installs configured Fish plugins. |
devbox/scripts/common.ps1 |
Provides shared PowerShell helpers. |
devbox/README.md |
Documents setup and safety behavior. |
devbox/Brewfile |
Defines Linuxbrew developer packages. |
devbox/bootstrap.ps1 |
Orchestrates provisioning phases. |
devbox/.gitattributes |
Enforces Unix line endings for Linux scripts. |
Review details
Suppressed comments (4)
devbox/scripts/ubuntu-bootstrap.sh:58
- The safe linker checks linked parents for its manifest, but this later write does not check
$HOME/.config/fish/conf.d. If that directory already links elsewhere,mkdir/mvwritesdevbox-brew.fishinto the linked target, violating the bootstrap's safety guarantee. Reject or safely handle linked parents before creating this managed file.
mkdir -p "$HOME/.config/fish/conf.d"
devbox/scripts/windows.ps1:9
--source wingetrestricts detection to packages installed from that source. An existing package installed from Microsoft Store or another source is therefore treated as missing, and the subsequent install can fail or attempt a second installation, contrary to the no-upgrade/idempotent behavior. Detect by exact ID without the source filter while retaining the source restriction on install.
& winget.exe list --id $id --exact --source winget --accept-source-agreements --disable-interactivity | Out-Host
symbolLink.js:150
- Windows file entries use
mode === 'copy', but this early return accepts a matching source symlink for every mode. A legacy link is consequently left in place instead of being converted to a copy, so source edits still propagate and the documented Windows copy isolation is bypassed. Only treat matching symlinks as no-ops for link mode.
if (existing?.isSymbolicLink()) {
const target = path.resolve(path.dirname(destination), await fs.readlink(destination));
if (target === source) return;
symbolLink.js:117
- Copy verification reads the destination through symlinks. A manually or legacy-symlinked Windows target that points to the source therefore passes
--verifyas a valid copy even though it violates copy mode. Check the destination withlstatand require a regular file before comparing bytes.
if (entry.mode === 'copy') {
if (!(await fs.readFile(entry.source)).equals(await fs.readFile(entry.destination))) {
- Files reviewed: 20/20 changed files
- Comments generated: 4
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| grep -Fxq "$fish" /etc/shells || printf '%s\n' "$fish" >> /etc/shells | ||
| [[ $(getent passwd "$user" | cut -d: -f7) == "$fish" ]] || usermod --shell "$fish" "$user" | ||
| # Preserve other WSL settings; update only the default user in its INI section. | ||
| /home/linuxbrew/.linuxbrew/bin/python3 - "$user" <<'PY' |
Comment on lines
+24
to
+28
| $bootstrap = Join-Path $repo 'devbox\bootstrap.ps1' | ||
| if (-not (Test-Path -LiteralPath $bootstrap)) { | ||
| throw 'Bootstrap files are not published or the existing checkout is outdated. Update it explicitly, preserving local changes.' | ||
| } | ||
| pwsh -NoLogo -NoProfile -File $bootstrap -Phase All |
| "distro": "Ubuntu-24.04", | ||
| "linuxUser": "", | ||
| "homebrewInstallerRevision": "8949852f785a3bacaba2a979d0790337950b0a4a", | ||
| "nodeVersion": "22", |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add Dev Box YAML, phased Windows and Ubuntu provisioning, safe dotfile installation, documentation, and regression tests. Use Linuxbrew for Ubuntu developer tools and reserve apt for OS prerequisites.