Compare commits
2 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| fabf1274aa | |||
| 5972a2c535 |
@@ -543,7 +543,12 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
EXPECTED_PI_VERSION: ${{ needs.resolve-versions.outputs.pi_version }}
|
EXPECTED_PI_VERSION: ${{ needs.resolve-versions.outputs.pi_version }}
|
||||||
EXPECTED_MEMPALACE_VERSION: ${{ needs.resolve-versions.outputs.mempalace_version }}
|
EXPECTED_MEMPALACE_VERSION: ${{ needs.resolve-versions.outputs.mempalace_version }}
|
||||||
run: bash scripts/smoke-test.sh pi-devbox:smoke
|
run: |
|
||||||
|
# Single source of truth for the node major is Dockerfile.base's ARG.
|
||||||
|
# Asserting the BUILT image matches it also catches a stale cached layer.
|
||||||
|
EXPECTED_NODE_MAJOR=$(sed -n 's/^ARG NODE_VERSION=\([0-9][0-9]*\).*/\1/p' Dockerfile.base)
|
||||||
|
export EXPECTED_NODE_MAJOR
|
||||||
|
bash scripts/smoke-test.sh pi-devbox:smoke
|
||||||
|
|
||||||
# ── Phase 3b: amd64 smoke for the studio variant ────────────────────
|
# ── Phase 3b: amd64 smoke for the studio variant ────────────────────
|
||||||
# Additive + independent of the core `smoke` job: gates ONLY
|
# Additive + independent of the core `smoke` job: gates ONLY
|
||||||
@@ -606,7 +611,12 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
EXPECTED_PI_VERSION: ${{ needs.resolve-versions.outputs.pi_version }}
|
EXPECTED_PI_VERSION: ${{ needs.resolve-versions.outputs.pi_version }}
|
||||||
EXPECTED_MEMPALACE_VERSION: ${{ needs.resolve-versions.outputs.mempalace_version }}
|
EXPECTED_MEMPALACE_VERSION: ${{ needs.resolve-versions.outputs.mempalace_version }}
|
||||||
run: bash scripts/smoke-test.sh pi-devbox:smoke-studio
|
run: |
|
||||||
|
# Single source of truth for the node major is Dockerfile.base's ARG.
|
||||||
|
# Asserting the BUILT image matches it also catches a stale cached layer.
|
||||||
|
EXPECTED_NODE_MAJOR=$(sed -n 's/^ARG NODE_VERSION=\([0-9][0-9]*\).*/\1/p' Dockerfile.base)
|
||||||
|
export EXPECTED_NODE_MAJOR
|
||||||
|
bash scripts/smoke-test.sh pi-devbox:smoke-studio
|
||||||
|
|
||||||
# ── Phase 4: multi-arch publish ─────────────────────────────────────
|
# ── Phase 4: multi-arch publish ─────────────────────────────────────
|
||||||
build-variant:
|
build-variant:
|
||||||
|
|||||||
+56
-3
@@ -11,6 +11,53 @@ Pre-v1.0.0 tags followed the pi npm version (`v{pi_version}[letter]`).
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## Unreleased
|
||||||
|
|
||||||
|
**A test that was quietly checking nothing, and a version number that was wrong.**
|
||||||
|
Both found by delegating a read-only audit of this repo to a headless worker
|
||||||
|
(`pi-toolkit` `bin/pi-task`) and then spot-checking its pointers from the
|
||||||
|
filesystem — 5 of 5 held, and it also corrected a false premise planted in its
|
||||||
|
own brief.
|
||||||
|
|
||||||
|
**The node major is now asserted, not merely printed.**
|
||||||
|
`scripts/smoke-test.sh` ran `run "node" "node --version"`, which asserts only
|
||||||
|
that the binary exists and exits 0 — the printed version was compared to
|
||||||
|
nothing. The line above it has always used `run_expect` against
|
||||||
|
`$EXPECTED_PI_VERSION` for `pi`, so the suite *looked* like it covered node.
|
||||||
|
**A node major bump would have passed the whole smoke suite silently.** Worse,
|
||||||
|
this is where the "node v22.23.2 verified" line in the v1.8.13 recreate notes
|
||||||
|
came from: printed output, not an assertion — an expectation stated up front and
|
||||||
|
then falsified by the check.
|
||||||
|
|
||||||
|
Now gated on `EXPECTED_NODE_MAJOR`, which CI derives from `Dockerfile.base`'s
|
||||||
|
`ARG NODE_VERSION` — the single source of truth, and the *only* hard node pin in
|
||||||
|
the repo (`Dockerfile.variant` has no node install at all, so the two Dockerfiles
|
||||||
|
cannot disagree). That also catches a stale cached layer whose node disagrees
|
||||||
|
with the declared ARG. Unset ⇒ previous behaviour, so nothing breaks for anyone
|
||||||
|
running the suite by hand.
|
||||||
|
|
||||||
|
Verified two-sided, because a silent failure here reintroduces the exact bug it
|
||||||
|
fixes: the `sed` derivation yields `22` (an empty result would disable the
|
||||||
|
assertion silently); `grep -Fq "v22."` matches `v22.23.2`; `"v24."` does **not**
|
||||||
|
match, so a wrong major is caught; `"v2."` does not prefix-collide. The workflow
|
||||||
|
YAML was re-parsed after editing (9 jobs).
|
||||||
|
|
||||||
|
**v1.8.13's agent-browser version was wrong.** That entry said "the image's own
|
||||||
|
0.35.2". The image ships **0.36.0** — `/usr/lib/node_modules/agent-browser` at
|
||||||
|
0.36.0 with `engines.node >=24.0.0`, and no 0.35.2 exists anywhere in the image.
|
||||||
|
The sentence was also internally incoherent, contrasting 0.36.0 against a version
|
||||||
|
that is not present. Corrected in place with a visible note, since that entry is
|
||||||
|
already released. **The reasoning survives untouched**: the engines floor really
|
||||||
|
is vestigial, because `/usr/bin/agent-browser` is a prebuilt aarch64 ELF invoked
|
||||||
|
directly and never through node — which is exactly why 0.36.0 runs fine on
|
||||||
|
22.23.2, consistent with the runtime proof collected on 2026-09-07 and with the
|
||||||
|
retraction of the earlier false "0.36.0 requires node >= 24" alert.
|
||||||
|
|
||||||
|
No image content changes: `NODE_VERSION` still 22, no pins moved. This is a test
|
||||||
|
and a docs correction only.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## v1.8.13 — 2026-09-06
|
## v1.8.13 — 2026-09-06
|
||||||
|
|
||||||
**Version audit + three pins moved, one deliberately not moved.** `pi`
|
**Version audit + three pins moved, one deliberately not moved.** `pi`
|
||||||
@@ -56,9 +103,15 @@ identically to the 0.84.4 control, so "alive" could be distinguished from
|
|||||||
safe: all five prebuilt native addons in pi use NAPI (ABI-stable, no
|
safe: all five prebuilt native addons in pi use NAPI (ABI-stable, no
|
||||||
NODE_MODULE_VERSION lock, no binding.gyp), nothing in the image declares a node
|
NODE_MODULE_VERSION lock, no binding.gyp), nothing in the image declares a node
|
||||||
CEILING, and the install is one token (`setup_${NODE_VERSION}.x`). agent-browser
|
CEILING, and the install is one token (`setup_${NODE_VERSION}.x`). agent-browser
|
||||||
0.36.0 declares `engines.node >=24`, but that field is vestigial for the
|
0.36.0 declares `engines.node >=24.0.0`, but that field is vestigial for the
|
||||||
artifact actually shipped: the image's own 0.35.2 declares the same floor and
|
artifact actually shipped: `/usr/bin/agent-browser` is the prebuilt aarch64 ELF
|
||||||
runs fine on 22.23.2 as a prebuilt aarch64 ELF. The reason to wait is
|
`bin/agent-browser-linux-arm64`, invoked directly and never through node, so npm's
|
||||||
|
engines floor is never enforced at runtime — verified running under 22.23.2 in
|
||||||
|
this image. (Corrected 2026-09-07: this paragraph originally said "the image's own
|
||||||
|
0.35.2 declares the same floor". That was wrong and incoherent — it contrasted
|
||||||
|
0.36.0 against a 0.35.2 that does not exist in the image. There is exactly one
|
||||||
|
agent-browser present, `/usr/lib/node_modules/agent-browser` at 0.36.0. The
|
||||||
|
argument is unaffected; only the version was wrong.) The reason to wait is
|
||||||
attribution, not compatibility — this release already moves pi a minor,
|
attribution, not compatibility — this release already moves pi a minor,
|
||||||
mempalace a minor and bakes a Studio RC, so adding a node major would leave four
|
mempalace a minor and bakes a Studio RC, so adding a node major would leave four
|
||||||
suspects if the image misbehaves. Worth doing as its own release with the smoke
|
suspects if the image misbehaves. Worth doing as its own release with the smoke
|
||||||
|
|||||||
+13
-1
@@ -5,6 +5,7 @@
|
|||||||
#
|
#
|
||||||
# Verifies:
|
# Verifies:
|
||||||
# - pi binary present and (if EXPECTED_PI_VERSION set) matches CI's resolved version
|
# - pi binary present and (if EXPECTED_PI_VERSION set) matches CI's resolved version
|
||||||
|
# - node MAJOR matches Dockerfile.base's ARG NODE_VERSION (if EXPECTED_NODE_MAJOR set)
|
||||||
# - mempalace core matches the audited pin (if EXPECTED_MEMPALACE_VERSION set)
|
# - mempalace core matches the audited pin (if EXPECTED_MEMPALACE_VERSION set)
|
||||||
# - new v1.0.0 base additions (pandoc, graphviz, imagemagick, yq, tealdeer)
|
# - new v1.0.0 base additions (pandoc, graphviz, imagemagick, yq, tealdeer)
|
||||||
# - typst PDF engine for pandoc (v1.4.0) — `pandoc --pdf-engine=typst`
|
# - typst PDF engine for pandoc (v1.4.0) — `pandoc --pdf-engine=typst`
|
||||||
@@ -91,7 +92,18 @@ if [ -n "${EXPECTED_PI_VERSION:-}" ]; then
|
|||||||
else
|
else
|
||||||
run "pi" "pi --version"
|
run "pi" "pi --version"
|
||||||
fi
|
fi
|
||||||
run "node" "node --version"
|
# Until 2026-09-07 this was a bare `run "node" "node --version"`, which asserts
|
||||||
|
# only that the binary exists and exits 0 — the printed version was never
|
||||||
|
# compared to anything. A node major bump would therefore have passed this suite
|
||||||
|
# SILENTLY, while a reader skimming it would reasonably assume node regressions
|
||||||
|
# were covered. EXPECTED_NODE_MAJOR closes that: CI derives it from
|
||||||
|
# Dockerfile.base's ARG NODE_VERSION (the single source of truth), so this also
|
||||||
|
# catches a stale cached layer whose node does not match the declared ARG.
|
||||||
|
if [ -n "${EXPECTED_NODE_MAJOR:-}" ]; then
|
||||||
|
run_expect "node major matches Dockerfile ARG" "node --version" "v${EXPECTED_NODE_MAJOR}."
|
||||||
|
else
|
||||||
|
run "node" "node --version"
|
||||||
|
fi
|
||||||
run "git" "git --version"
|
run "git" "git --version"
|
||||||
run "aws" "aws --version"
|
run "aws" "aws --version"
|
||||||
run "uv" "uv --version"
|
run "uv" "uv --version"
|
||||||
|
|||||||
Reference in New Issue
Block a user