Standalone Python cannot locate the system CA bundle on this NixOS host. Use the shell-staged uv to prepare the independent PM runtime before PM fetches managed Python. Declare and lock truststore in that runtime, then activate it before CLI and worker imports construct HTTPS clients. Make setup's awk pin reader follow object nesting rather than indentation. Use the same reader for tool versions and artifact fields. Verified cold activation with CA overrides removed, pinned Python and uv downloads, pm doctor, and a public worker HTTPS install. The targeted suite passed 56 tests with one Windows-only skip. The TLS regression fails when truststore is installed but entrypoint activation is removed. Bash syntax and Ruff checks passed. The full suite was not run. Two additional setup-toolchain tests fail on unchanged HEAD because their fixtures reach the real home before home isolation. CI bootstrap unification is not part of this change.
15 lines
372 B
Python
15 lines
372 B
Python
"""CLI entry after the isolated interpreter has been selected."""
|
|
from pathlib import Path
|
|
import sys
|
|
|
|
import truststore
|
|
|
|
# PM's import closure constructs HTTPS clients; install platform trust first.
|
|
truststore.inject_into_ssl()
|
|
sys.path.insert(0, str(Path(__file__).resolve().parents[1]))
|
|
|
|
from pm.cli import main
|
|
|
|
if __name__ == "__main__":
|
|
raise SystemExit(main())
|