fix: restore worker builds, Convex contracts and honest release gates - #621
fix: restore worker builds, Convex contracts and honest release gates#621HomenShum wants to merge 30 commits into
Conversation
Commit a root lock from unchanged package declarations using npm11.5.2 and the existing legacy-peer-deps setting. Pin the Node22 base, share install policy across stages, and remove COPY instructions for a deleted script. Include only the public root npm setting in Cloud Build upload context; exclude dotenv and registry-token files. Five controlled credential canaries are excluded by the actual gcloud file-selection command, without upload. Add a Linux CI container build and isolated startup/rejection proof. Local Docker failed during socket startup, so container proof remains pending. Fresh resolution has31 audit findings/13high; no security acceptance, provider proof, image publication or deployment is claimed. Keep the candidate draft.
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
PR size advisoryThis PR adds 34499 lines of substantive change. CONTRIBUTING.md defines a soft limit of ~400 LOC. If the PR is genuinely cohesive (e.g. an architecture map, a generated migration, a deletion of a dead module), no action is needed. Otherwise consider:
This is advisory — it does not block the merge. |
The first Linux container job failed before Docker: actions/checkout with credential persistence disabled runs submodule cleanup, which exits128 for the accidentally tracked Claude worktree without a .gitmodules URL. Remove only that Gitlink from future source checkouts. Its target commit remains an ancestor of main; the three inspected local directories are empty and untouched. Keep credential persistence disabled and the existing ignore rule. Capture base-build diagnostics on PR runs so the failed initial checkout does not leave the actual before-build proof missing.
The first shared runtime suite had405 passes and one failure because the old text check required Node20 literally. Read the configured Node major and package-manager version instead, require a pinned base and shared policy, compare the root lock's direct graph and check that actual COPY sources exist. Retain the existing emitted-ESM, production-only, asset, credential exclusion and ownership checks. This source guard does not replace the actual Linux container build/startup proof, which remains pending.
The clean Linux image built successfully but Node crashed before main because the entrypoint imports dotenv, which npm ci --omit=dev correctly excluded. Move its existing version range into runtime dependencies. Regenerate the lock with declared npm11.5.2; only root metadata and dotenv's dev flag change. Keep all233 version ranges and resolved package/integrity values unchanged. Record the real failure and optional capability/typecheck limits in the runbook. Actual startup after this change remains pending the isolated container gate.
Scope Axios0.33.0 to paged-request without changing application ranges or unrelated lock resolutions. Retain a real npm-api pagination and HTTP suite covering concurrency, repeated rounds, failure/retry and credential boundaries. Run it against the production install in the isolated worker container gate. On Windows the same11 scenarios reproduce inherited credentials reaching a controlled server with0.21.4 (10pass/1fail);0.33.0 passes11/11. The root audit falls from31 affected packages/13high to27/9; production-only remains13/1. The installed component does not call npm-api in its current source. Its separate token-argument logging finding is documented as an open release hold. Fresh Linux image/startup/contracts and independent review remain pending.
Published convex-oss-stats0.8.2 logs its full sync arguments before provider work, including the GitHub token. Add a package-specific postinstall hook that verifies published/repaired hashes of both entrypoints before removing only that statement. Keep API arguments, token forwarding and scheduling. Default clean installs apply the repair. Docker and the legacy thin manifest include its required source. The root lock only gains hasInstallScript; all2451 resolved package records remain unchanged. Same six real-handler/install scenarios: unpatched2pass/4token-leakfail, patched6pass. Cover failure, schedule replacement, concurrent/repeated sync, idempotent installation and preflight refusal on source/version drift. Fresh Linux startup/HTTP/token contracts and independent review are pending. The legacy thin generator retains its pre-existing syntax/layout gaps.
Scope Undici 6.28.1 to AI SDK provider-utils while preserving its URL, DNS and redirect guards. Match the direct parent range without changing any application dependency range. Inspect the three-record lock delta. Same native contracts: old 10 passes/1 excessive-encoding failure, patched 11 passes. Both versions retrieve the bounded public tarball through real native fetch/DNS and verify its published SHA512 identity. Extend the actual Linux production-image gate with these download lanes. Production audit has zero high findings, with 12 lower-severity findings remaining; the development-inclusive graph still has 9 high findings. Fresh Linux proof and independent review remain pending at authoring.
Scope SDK0.91.1 to the existing Pi-AI dependency path, reusing the patched root client and removing only its obsolete nested0.90.0 lock entry. Keep all application ranges and the model/provider interface unchanged. Both native clients pass9 actual local HTTP/SSE scenarios. Both memory helpers pass4 operation scenarios; Windows explicitly skips2 POSIX cases. Require the Linux image to reproduce exactly2 old permission failures and pass all6 scenarios against the installed patched dependency. The canary retrieves one fixed public tarball with a4MiB cap and published SHA512, extracting only3 required fixture modules. It never accesses personal memory or enters the production dependency graph. Production audit9/0high, full24/9high. Fresh Linux proof and independent review remain pending at authoring; retain the draft and remaining holds.
Keep exact source and copy available through lazy-renderer failure, remove lifetime snippet caches, and retire the unused Prism wrapper dependency chain. Add focused regression coverage to CI.
❌ Dogfood Visual QA Gate: FAILED
ArtifactsDownload the Generated by Dogfood QA Gate |
Rendered contrast measured below target with the dark destructive background token. Use readable error foregrounds and suppress feedback-class transitions.
Guard Convex dynamic codegen at the published 1.45.0 bytes, retain per-module inference at repository scale, and replace the empty application check with actual source and caller checks. Preserve failed diagnostics in CI; full application typing remains unresolved.
Vercel preflight failed:
|
Vercel preflight failed:
|
Vercel preflight failed:
|
Vercel preflight failed:
|
Vercel preflight failed:
|
Vercel preflight failed:
|
Vercel preflight failed:
|
Vercel preflight failed:
|
Vercel preflight failed:
|
Vercel preflight failed:
|
Vercel preflight failed:
|
…son (#625) One shared resolver (src/project.ts) honoring convex.json functions with convex/, src/convex, backend/convex fallbacks; all 19 tool files import it; the architect single-file test derives the schema path from it; projectResolution.test.ts pins the behaviour; the real-backend audit test gets the same 30s budget as the neighbouring repo scans. Fixes the nightly Convex MCP Eval Gate red since PR #590 moved the backend. Carved out of #621.
Repair worker build reproducibility and concrete Convex contracts while keeping release failures visible. Settings now opens under normal motion, restores focus to its connected opener, and keeps its existing controls reachable on phones: compact top navigation replaces the fixed sidebar, while service rows and key-input controls wrap within the content pane. Desktop keeps its sidebar and measured shell geometry.
The cumulative implementation includes:
false,false,autosurvive readback while owner admission and unset/no-auth defaults remain.Validation for candidate
b162b56ad890d41b2252a8e132d902efdf123a70:b803cb50first CI is FAIL: Linux application 1,290 diagnostics, codegen 1,046 across278 files, Build skipped. Runtime smoke 587/43, renderer 21/5, generator 7/7 and then-current API checks 5/5 pass. Preflight completes in208.420s and fails on actual application typing, without heap exhaustion. These shared results precede the finite-return follow-up.Keep this PR draft. Full typing, the existing motion-variants diagnostic, authenticated/provider workflows, anonymous cold-load/loader rejection, broader deletion coverage, production adoption and complete product acceptance remain open. Separate Attrition HTTP405 failures remain suppressed and unresolved. This publication does not merge, deploy, retrieve provider keys or perform live destructive actions.
Workflow input follow-up
527db79c6c0b85e87892e60c49f6653b73666a88The issue-comment packet action now reads event text in one static JavaScript step, serializes JSON requests and formats bounded response data without shell/step-output/sed source generation. Marker extraction is case-insensitive and preserves the original query. HTTPS origin checks, redirect refusal,60-second response deadline,256KiB body limit and awaited failure paths keep malformed or failed requests from producing a success comment. Bot replies are excluded. Attrition's manual URL is bound through the environment; its separate routing and suppressed benchmark failures remain open.
Independent scoped review accepted all five files. Actual local proof passed16/16 with60 loopbackHTTP captures, including24concurrent and20sustained queries, with intercepted GitHub posts and no provider request/public comment. The earlier Bash-PATH failure and read-only TAP decoding correction remain preserved. No app/compiler/native proof was replayed for publication. Existing full typing still fails; this narrow follow-up does not certify the application or repair unrelated errors.
NodeBench Packet is disabled_manually as an explicit reversible security hold because the vulnerable default-branch source remains unreplaced. Keep it disabled until the reviewed replacement is on default main and independently read back. CI and Attrition remain active; the hold is not CI-green or a claim that main is repaired.
The first shared CI for this exact workflow-input head is pending. No CI rerun, main merge, workflow reenabling or deployment is part of this publication.