From fabf1274aacea500e9905cbf3bd0df415c8b700f Mon Sep 17 00:00:00 2001 From: Joakim Persson Date: Mon, 7 Sep 2026 21:17:06 +0200 Subject: [PATCH] docs(changelog): Unreleased section for the smoke node assertion + agent-browser correction Summarises what changed since v1.8.13: the node-major assertion (a bump would have passed the suite silently), the two-sided verification of the derivation, and the v1.8.13 agent-browser 0.35.2 -> 0.36.0 correction. No image content changes; NODE_VERSION still 22. --- CHANGELOG.md | 47 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7dd88da..602c169 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -11,6 +11,53 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`). --- +## Unreleased + +**A test that was quietly checking nothing, and a version number that was wrong.** +Both found by delegating a read-only audit of this repo to a headless worker +(`pi-toolkit` `bin/pi-task`) and then spot-checking its pointers from the +filesystem — 5 of 5 held, and it also corrected a false premise planted in its +own brief. + +**The node major is now asserted, not merely printed.** +`scripts/smoke-test.sh` ran `run "node" "node --version"`, which asserts only +that the binary exists and exits 0 — the printed version was compared to +nothing. The line above it has always used `run_expect` against +`$EXPECTED_PI_VERSION` for `pi`, so the suite *looked* like it covered node. +**A node major bump would have passed the whole smoke suite silently.** Worse, +this is where the "node v22.23.2 verified" line in the v1.8.13 recreate notes +came from: printed output, not an assertion — an expectation stated up front and +then falsified by the check. + +Now gated on `EXPECTED_NODE_MAJOR`, which CI derives from `Dockerfile.base`'s +`ARG NODE_VERSION` — the single source of truth, and the *only* hard node pin in +the repo (`Dockerfile.variant` has no node install at all, so the two Dockerfiles +cannot disagree). That also catches a stale cached layer whose node disagrees +with the declared ARG. Unset ⇒ previous behaviour, so nothing breaks for anyone +running the suite by hand. + +Verified two-sided, because a silent failure here reintroduces the exact bug it +fixes: the `sed` derivation yields `22` (an empty result would disable the +assertion silently); `grep -Fq "v22."` matches `v22.23.2`; `"v24."` does **not** +match, so a wrong major is caught; `"v2."` does not prefix-collide. The workflow +YAML was re-parsed after editing (9 jobs). + +**v1.8.13's agent-browser version was wrong.** That entry said "the image's own +0.35.2". The image ships **0.36.0** — `/usr/lib/node_modules/agent-browser` at +0.36.0 with `engines.node >=24.0.0`, and no 0.35.2 exists anywhere in the image. +The sentence was also internally incoherent, contrasting 0.36.0 against a version +that is not present. Corrected in place with a visible note, since that entry is +already released. **The reasoning survives untouched**: the engines floor really +is vestigial, because `/usr/bin/agent-browser` is a prebuilt aarch64 ELF invoked +directly and never through node — which is exactly why 0.36.0 runs fine on +22.23.2, consistent with the runtime proof collected on 2026-09-07 and with the +retraction of the earlier false "0.36.0 requires node >= 24" alert. + +No image content changes: `NODE_VERSION` still 22, no pins moved. This is a test +and a docs correction only. + +--- + ## v1.8.13 — 2026-09-06 **Version audit + three pins moved, one deliberately not moved.** `pi`