Skip to content

fix(release): validate published consumer compatibility - #259

Merged
f0rr0 merged 2 commits into
mainfrom
f0rr0/wasix-direct-carrier-compatibility
Oct 7, 2026
Merged

f0rr0 merged 2 commits into
mainfrom
f0rr0/wasix-direct-carrier-compatibility

Conversation

@f0rr0

@f0rr0 f0rr0 commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Summary

A clean install of @oliphaunt/wasix-ts@0.2.1 selects N-API carriers 0.2.0 whose embedded runtime is 0.3.0, while the SDK requires 0.3.1. The SDK rejects the carrier before opening a database. The mismatch affects all four carrier manifests and was reproduced on Linux through actor, /direct, /worker, and /server consumers.

The wider audit found three additional incompatible released combinations: all seven WASIX extensions against the TypeScript SDK, all fourteen external-extension/Rust-SDK pairs, and Kotlin 0.3.1 against all seven Android extensions. All 27 products and 265 declared registry identities were inventoried; metadata availability did not establish consumer compatibility.

Source qualification passed with workspace fixtures, while publication checked the selected packages and reused frozen bytes. Historical dependencies installed by customers were outside the effective compatibility proof. The independent-pin design and dependency-identity follow-up require preserving historical package identity and selecting fresh compatible products. This change enforces that requirement on the actual release combination.

  • Check selected SDKs, their historical dependency pins, transitive SDK consumers, external-extension runtime contracts, and published Cargo facade API requirements before candidate closure and registry admission.
  • Run the same admission gate in generated release PR CI, main release CI, and selected main qualification dispatches before planning. A rejected combination blocks Required and Qualified.
  • Validate pristine SDK/N-API tarballs before freezing and after checksum verification when packing or installing reused capsules. Check every installed WASIX SDK's actual resolved carrier during public npm verification, including nested and unselected dependencies.
  • Give Cargo facade generation explicit release ownership; use compatible SemVer requirements for SDK/build-helper/binding APIs while retaining exact payload identities. Give WASIX tools an owned SDK compatibility pin and validate its runtime against that SDK.
  • Fix historical tag alias resolution and document the admission, reuse, and recovery requirements.
  • Restrict public-consumer coordinator cleanup to its owning shell. CI exposed a background child receiving a signal before exec and running the inherited cleanup trap, killing sibling probes and deleting shared logs. A deterministic regression covers successful and failed consumers with inherited child traps.

Release Intent

  • Package/API/runtime change: PR title uses fix:.
  • Docs/CI/repository-only change: no release intended.
  • Source/input/runtime asset change: source pins, generated metadata, and release metadata affectedness are current.

This PR changes packaging and release enforcement. Already-published versions remain unchanged. Recovery requires a fresh Release Please candidate with compatible SDK, N-API, and extension products, exact-SHA hosted qualification on the declared targets, and a new frozen publication lock. Kotlin also needs a fresh default-runtime/extension combination. Publication is separate from merging this PR.

Verification

  • Moon affected checks and tests passed.
  • Product-specific smoke/package/perf checks when product behavior or artifacts changed.

Validation includes 23 owner Moon tasks; SDK/tools typechecks, unit tests and packaging; the complete release-tools suite; release format/lint/metadata checks; and the pinned actionlint/zizmor/workflow behavior gate. The focused consumer, frozen-lock, and installed-consumer suites pass 48 tests. A real Cargo facade consumer compiles with newer patch API dependencies.

Regression fixtures prove admission failure stops generated-release and selected-main planning, checksum-consistent incompatible reused capsules fail staged validation, and historical admission works in a clean checkout without node_modules. The actual historical release combinations are rejected; matching older native TypeScript, Swift, and React Native pins pass.

The incident audit reproduced clean Linux npm failures, all fourteen real Cargo resolution failures, and the published Android plugin's rejection of all fourteen external manifests. These are not full browser, macOS, Windows, Linux arm64, or mobile app execution tests. The coordinator regression fails before the ownership guard and passes afterward on Bash 5 and Bash 3.2; 30 concurrent reproductions also pass after the fix. Hosted qualification for the updated commit remains pending.

@vercel

vercel Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
oliphaunt-docs Skipped Skipped Oct 7, 2026 2:55am UTC

@f0rr0
f0rr0 merged commit e918d6a into main Oct 7, 2026
30 of 45 checks passed
@f0rr0
f0rr0 deleted the f0rr0/wasix-direct-carrier-compatibility branch October 7, 2026 03:09

This branch was previously deployed

1 inactive deployment
Preview — f4e1c507 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant