Repository navigation
fix(release): validate published consumer compatibility - #259
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A clean install of
@oliphaunt/wasix-ts@0.2.1selects N-API carriers0.2.0whose embedded runtime is0.3.0, while the SDK requires0.3.1. The SDK rejects the carrier before opening a database. The mismatch affects all four carrier manifests and was reproduced on Linux through actor,/direct,/worker, and/serverconsumers.The wider audit found three additional incompatible released combinations: all seven WASIX extensions against the TypeScript SDK, all fourteen external-extension/Rust-SDK pairs, and Kotlin
0.3.1against all seven Android extensions. All 27 products and 265 declared registry identities were inventoried; metadata availability did not establish consumer compatibility.Source qualification passed with workspace fixtures, while publication checked the selected packages and reused frozen bytes. Historical dependencies installed by customers were outside the effective compatibility proof. The independent-pin design and dependency-identity follow-up require preserving historical package identity and selecting fresh compatible products. This change enforces that requirement on the actual release combination.
RequiredandQualified.execand running the inherited cleanup trap, killing sibling probes and deleting shared logs. A deterministic regression covers successful and failed consumers with inherited child traps.Release Intent
fix:.This PR changes packaging and release enforcement. Already-published versions remain unchanged. Recovery requires a fresh Release Please candidate with compatible SDK, N-API, and extension products, exact-SHA hosted qualification on the declared targets, and a new frozen publication lock. Kotlin also needs a fresh default-runtime/extension combination. Publication is separate from merging this PR.
Verification
Validation includes 23 owner Moon tasks; SDK/tools typechecks, unit tests and packaging; the complete release-tools suite; release format/lint/metadata checks; and the pinned actionlint/zizmor/workflow behavior gate. The focused consumer, frozen-lock, and installed-consumer suites pass 48 tests. A real Cargo facade consumer compiles with newer patch API dependencies.
Regression fixtures prove admission failure stops generated-release and selected-main planning, checksum-consistent incompatible reused capsules fail staged validation, and historical admission works in a clean checkout without
node_modules. The actual historical release combinations are rejected; matching older native TypeScript, Swift, and React Native pins pass.The incident audit reproduced clean Linux npm failures, all fourteen real Cargo resolution failures, and the published Android plugin's rejection of all fourteen external manifests. These are not full browser, macOS, Windows, Linux arm64, or mobile app execution tests. The coordinator regression fails before the ownership guard and passes afterward on Bash 5 and Bash 3.2; 30 concurrent reproductions also pass after the fix. Hosted qualification for the updated commit remains pending.