feat(mt#3866): Give calibration records an identity, and report disti… #2454
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: npm Pack Install Smoke | |
| # mt#3949 — consumer-side gate for the npm publish channel. | |
| # | |
| # Every check the publish path had was a PUBLISHER-side check: does the package | |
| # exist, do we own the name, did OIDC authenticate, is provenance attached. All | |
| # of them pass on a package nobody can install — which is exactly what shipped. | |
| # `@edobry/minsky@0.1.1` declared two dependencies at `workspace:*`, a protocol | |
| # no registry client can resolve, so every install outside this monorepo failed | |
| # at resolution. It was live and uninstallable for a day, across two versions. | |
| # | |
| # This job runs `scripts/verify-npm-pack-install.ts`, which packs the exact | |
| # artifact `npm publish` would upload and installs it — locally and through the | |
| # global path, into a throwaway BUN_INSTALL prefix — then runs the installed | |
| # `minsky --version`. Verifying against the packed tarball is what makes this a | |
| # PRE-publish gate: checking after publishing costs an immutable version number | |
| # per attempt, which is how the original defect was found rather than prevented. | |
| # | |
| # mt#3887: also runs the script's step 4b, which applies migrations against the | |
| # Postgres service below using the INSTALLED package's dist/ layout. This is the | |
| # falsifier for excluding dist/storage/migrations/pg/meta/*_snapshot.json from | |
| # files[] — those are drizzle-kit's generate-time-only metadata, and this job is | |
| # what proves apply-time (`persistence migrate --execute`) never needed them, | |
| # against a real database rather than by reading drizzle's docs. | |
| # | |
| # Sibling gates, and why this is not either of them: | |
| # - bundle-boot-smoke: does the thing we DEPLOY start? (dist/minsky.js on Railway) | |
| # - docker-build-smoke: does the production image BUILD? | |
| # - this: can an end user INSTALL and run what we PUBLISH? | |
| # | |
| # Not registered as a merge-gate required check — that list is owned by | |
| # `.claude/hooks/require-review-before-merge.ts` and adding to it is a separate, | |
| # deliberate decision. | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| workflow_dispatch: | |
| env: | |
| # Secondary hedge for the mt#3623 install flake: disables the streaming | |
| # tarball path implicated upstream (oven-sh/bun#34821). The per-step retry | |
| # loop remains the load-bearing mitigation. Remove both when a bun release | |
| # carries the upstream fix (mt#3835 tracks the retirement). | |
| BUN_FEATURE_FLAG_DISABLE_STREAMING_INSTALL: "1" | |
| jobs: | |
| npm-pack-install-smoke: | |
| name: npm-pack-install-smoke | |
| runs-on: ubuntu-latest | |
| services: | |
| postgres: | |
| # pgvector-enabled image, matching cold-start-migrate.yml — the schema uses the | |
| # `vector` type and the bootstrap snapshot runs CREATE EXTENSION IF NOT EXISTS vector. | |
| image: pgvector/pgvector:pg16 | |
| env: | |
| POSTGRES_USER: minsky_test | |
| POSTGRES_PASSWORD: minsky_test | |
| POSTGRES_DB: minsky_pack_smoke | |
| ports: | |
| - 5432:5432 | |
| options: >- | |
| --health-cmd pg_isready | |
| --health-interval 5s | |
| --health-timeout 5s | |
| --health-retries 10 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Setup Bun | |
| uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: "1.3.14" | |
| # `npm pack` and the publish workflow both run on npm's CLI; pin the same | |
| # Node major `publish-npm.yml` uses so the packed artifact matches. | |
| - name: Setup Node | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: "24" | |
| - name: Cache Bun install | |
| uses: actions/cache@v4 | |
| with: | |
| path: $HOME/.bun/install/cache | |
| key: bun-install-${{ runner.os }}-${{ hashFiles('bun.lock', 'services/reviewer/bun.lock') }} | |
| restore-keys: | | |
| bun-install-${{ runner.os }}- | |
| - name: Install dependencies | |
| run: for i in 1 2 3; do if bun install --frozen-lockfile --no-progress; then break; fi; if [ "$i" = 3 ]; then exit 1; fi; echo "bun install failed (mt#3623 tarball flake) - retry $i"; sleep 5; done | |
| # The script asserts the bundle is present rather than building it, so a | |
| # stale-bundle failure reads as a stale bundle instead of an install failure. | |
| - name: Build production bundle | |
| run: bun run build | |
| - name: Pack, install, and run the published artifact | |
| env: | |
| # mt#3887: enables step 4b (migration falsifier). Composed from parts, same | |
| # convention as cold-start-migrate.yml, to avoid gitleaks flagging a literal URL. | |
| DATABASE_URL: ${{ format('postgres://{0}:{1}@{2}:5432/{3}', 'minsky_test', 'minsky_test', 'localhost', 'minsky_pack_smoke') }} | |
| run: bun scripts/verify-npm-pack-install.ts |