Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
584 commits
Select commit Hold shift + click to select a range
77c816d
test(63-07): pin native doctor projection contract
Jul 17, 2026
1d3dec3
feat(63-07): format native doctor section
Jul 17, 2026
ef00cc9
docs(63-07): complete native diagnostics plan
Jul 17, 2026
d43cb8c
test(63-08): add failing native wake controller tests
Jul 17, 2026
ba3abb9
feat(63-08): implement closed native wake controller
Jul 17, 2026
b3871c7
test(63-08): add failing offline wake integration tests
Jul 17, 2026
fcb5c98
feat(63-08): integrate offline preflight native wake
Jul 17, 2026
710c990
feat(63-08): add native messaging permission
Jul 17, 2026
0296368
docs(63-08): complete native wake orchestration plan
Jul 17, 2026
ee345c0
fix(63-08): update native permission contract pins
Jul 18, 2026
a3e2bd4
fix(63-02): update serve lifecycle contract pin
Jul 18, 2026
1e03aa0
fix(63-08): update manifest parity boundary
Jul 18, 2026
0664430
fix(63-08): refresh phase 61 evidence pins
Jul 18, 2026
335fe66
fix(63-02): update inventory lifecycle pin
Jul 18, 2026
d75c28b
fix(63-08): update service worker import pins
Jul 18, 2026
36265d2
test(63-09): add native wake intent fence coverage
Jul 18, 2026
f4b9136
feat(63-09): fence native wake checking by send intent
Jul 18, 2026
f18bf5c
test(63-09): add wake convergence and a11y coverage
Jul 18, 2026
2e684ac
feat(63-09): style native wake checking accessibly
Jul 18, 2026
ed32be0
docs(63-09): complete intent-fenced native wake checking plan
Jul 18, 2026
bccb4fc
fix(63-09): update foreign-owner send pin
Jul 18, 2026
a53a181
test(63-10): add deferred native host UAT ledger
Jul 18, 2026
34cbae4
test(63-10): wire guarded native host matrix
Jul 18, 2026
894bbea
test(63-10): reconcile native host phase contract
Jul 18, 2026
ecc76a1
docs(63-10): complete native host contract plan
Jul 18, 2026
fdbebf5
fix(63-10): make contract clean-checkout safe
Jul 18, 2026
fecc98d
test(63-06): require production native host composition
Jul 18, 2026
c52f8a2
fix(63-06): compose production native host transactions
Jul 18, 2026
3b65834
test(63-07): require production native host doctor facts
Jul 18, 2026
7fb88f4
fix(63-07): compose production native host diagnostics
Jul 18, 2026
be06837
test(63-04): require recoverable wake lock publication
Jul 18, 2026
531b8b4
fix(63-04): make wake lock publication recoverable
Jul 18, 2026
88e5847
docs(63): record review remediation evidence
Jul 18, 2026
512b5e0
test(63-06): require npm-independent native CLI
Jul 18, 2026
3d9cdd7
fix(63-06): decouple native CLI from npm environment
Jul 18, 2026
688846e
test(63-05): require explicit Windows shadow absence
Jul 18, 2026
566887c
fix(63-05): fail closed on Windows shadow proof
Jul 18, 2026
e91a2d7
test(63-04): reproduce stale lock ABA takeover
Jul 18, 2026
cf02002
fix(63-04): serialize stale wake recovery
Jul 18, 2026
d8fced5
docs(63): record review remediation evidence
Jul 18, 2026
e1b9631
docs(63-11): pass blocking code review gate
Jul 18, 2026
a91f3e2
test(phase-63): lock registry helper security contract
Jul 18, 2026
409e638
fix(phase-63): harden Windows registry boundary
Jul 18, 2026
79db94f
docs(phase-63): record registry security remediation
Jul 18, 2026
6d868ee
test(63-11): track registry helper root gate
Jul 18, 2026
5f67a46
docs(63-11): pass refreshed code review gate
Jul 18, 2026
7488c39
docs(63-11): pass blocking security review gate
Jul 18, 2026
ff0727e
docs(63-11): pass blocking UI review gate
Jul 18, 2026
d3f7d2f
docs(63-11): complete blocking review plan
Jul 18, 2026
97be6c3
test(63-12): record reviewed focused gate evidence
Jul 18, 2026
dff2fc4
test(60): reproduce raw index stat refresh drift
Jul 18, 2026
c24e499
test(60): cover raw index mutation boundaries
Jul 18, 2026
ee04a6c
fix(60): restore benign raw index refreshes
Jul 18, 2026
0aa57d9
test(60): expose hidden index intent mutation
Jul 18, 2026
d81a1c5
test(60): harden raw index preservation cases
Jul 18, 2026
caffbd6
fix(60): preserve raw index intent atomically
Jul 18, 2026
45f1726
test(60): expose intent and conflict index semantics
Jul 18, 2026
782941c
fix(60): preserve complete index intent
Jul 18, 2026
dca791a
test(60): reproduce initial index snapshot race
Jul 18, 2026
6de3adc
fix(60): stabilize initial index snapshot
Jul 18, 2026
01ff3e7
test(60): make index intent fixture portable
Jul 18, 2026
4efed3d
docs(63-12): correct full-suite key link
Jul 18, 2026
1b789c3
fix(63-11): keep review verification index read-only
Jul 18, 2026
da2ce3b
test(63-12): record superseding focused gate evidence
Jul 20, 2026
4278f63
test(63-12): close automated validation with guarded full suite
Jul 20, 2026
a944a0f
docs(63-12): complete final validation gate plan
Jul 20, 2026
4994e15
docs(phase-63): complete phase execution
Jul 20, 2026
d5824f4
docs(phase-63): evolve PROJECT.md after phase completion
Jul 20, 2026
90e1fab
docs(64): smart discuss context
Jul 20, 2026
d7be6a7
docs(64): UI design contract
Jul 20, 2026
65ed4a3
docs(phase-64): add research and validation strategy
Jul 20, 2026
2d00c9b
docs(64): map OpenCode adapter patterns
Jul 20, 2026
e9d0081
feat: finalize MCP session replay and v0.9.91 release
Jul 20, 2026
7a8cf83
Merge origin/main into refinements
Jul 20, 2026
7f25bb0
docs(64): create phase plan
Jul 20, 2026
6bbf672
feat(64-01): add OpenCode stream drift gate
Jul 20, 2026
15ddf9f
fix(sheets): redact nested tab titles from sessions
Jul 20, 2026
2f8359b
fix(mcp): resolve token-only lifecycle ownership
Jul 20, 2026
b827ca8
docs(quick-260720-jb5): Patch Sheets session redaction and multi-tab …
Jul 20, 2026
5789df1
docs(64-01): complete OpenCode parser drift gate plan
Jul 20, 2026
0655d3c
fix(64-01): refresh generalized drift contract pins
Jul 20, 2026
3f0caef
docs(64-01): record guarded regression repair
Jul 20, 2026
e1e616f
test(64-02): define closed spawn contract
Jul 20, 2026
ce19337
feat(64-02): freeze provider topology contract
Jul 20, 2026
9e0c386
docs(64-02): complete topology contract plan
Jul 20, 2026
3ed0def
docs(64-02): advance project state
Jul 20, 2026
e4ab9fb
test(64-03): define role-aware runtime journal contract
Jul 20, 2026
6119fad
feat(64-03): version role-aware runtime journal
Jul 20, 2026
b19e835
docs(64-03): complete runtime journal plan
Jul 20, 2026
dfcb898
docs(64-03): advance project state
Jul 20, 2026
29b7322
test(64-04): add failing OpenCode detector contract
Jul 20, 2026
e9e66dc
feat(64-04): implement retained OpenCode detection
Jul 20, 2026
43d08af
test(64-04): add failing OpenCode profile contract
Jul 20, 2026
2a56f26
feat(64-04): declare hermetic OpenCode profile
Jul 20, 2026
c6e1c5b
test(64-04): add failing OpenCode attestation contract
Jul 20, 2026
c974add
feat(64-04): declare generic OpenCode attestations
Jul 20, 2026
4995abc
docs(64-04): complete OpenCode policy profile plan
Jul 20, 2026
be5de47
docs(64-04): advance project state
Jul 20, 2026
b04e97d
feat(64-05): expose OpenCode adapter atomically
Jul 20, 2026
3646673
test(64-05): update atomic adapter exposure contract
Jul 20, 2026
623cb59
test(64-05): update production registry parity
Jul 20, 2026
ba9371a
docs(64-05): summarize atomic OpenCode exposure
Jul 20, 2026
b192e81
docs(64-05): advance project state
Jul 20, 2026
98feac5
test(64-06): add failing inventory and doctor projection tests
Jul 20, 2026
18ca71b
feat(64-06): project OpenCode inventory and doctor evidence
Jul 20, 2026
5710031
test(64-06): add failing safe compatibility projection tests
Jul 20, 2026
716264e
feat(64-06): close the two-provider compatibility projection
Jul 20, 2026
dfd1c44
test(64-06): refresh bridge compatibility roster fixture
Jul 20, 2026
eef58ff
test(64-06): refresh canonical doctor source pin
Jul 20, 2026
3ea25c3
test(64-06): refresh runtime inventory identity fixture
Jul 20, 2026
8c1e9e1
test(64-06): refresh downstream inventory projection fixtures
Jul 20, 2026
e1c1f72
docs(64-06): complete evidence projection plan
Jul 20, 2026
1515a0a
docs(64-06): advance project state
Jul 20, 2026
360ffc1
test(64-07): add failing test for topology selection and replay fence
Jul 20, 2026
cb1c423
feat(64-07): interpret owned-server topology with replay fence
Jul 20, 2026
6b3e265
test(64-07): add failing test for owned health and secret binding
Jul 20, 2026
ee237fa
feat(64-07): verify owned lease with transient basic secret
Jul 20, 2026
58c9911
test(64-07): add failing test for bounded lease lifecycle
Jul 20, 2026
e71945d
feat(64-07): bound owned lease lifecycle and teardown
Jul 20, 2026
5bdaacf
docs(64-07): complete owned server lifecycle plan
Jul 20, 2026
27c4611
docs(64-07): advance project state
Jul 20, 2026
1c5a099
test(64-08): require policy attestations before task authority
Jul 20, 2026
973de77
feat(64-08): attest effective policy before spawning tasks
Jul 20, 2026
26bb157
test(64-08): enforce task-once and fallback stderr fences
Jul 21, 2026
0a7b211
feat(64-08): enforce task-once stderr replay fence
Jul 21, 2026
481b52a
test(64-08): require post-cleanup result publication
Jul 21, 2026
c29c91e
feat(64-08): publish results after cleanup truth
Jul 21, 2026
9cdcfdb
docs(64-08): complete supervisor authority barriers
Jul 21, 2026
dbe6722
test(64-09): add canonical provider preflight coverage
Jul 21, 2026
b217baa
feat(64-09): canonicalize shipped provider preflight
Jul 21, 2026
3c28358
test(64-09): add provider-isolated consent coverage
Jul 21, 2026
dcffd25
feat(64-09): isolate delegation consent by provider
Jul 21, 2026
e0d1d90
test(64-09): add immutable provider routing coverage
Jul 21, 2026
e227606
feat(64-09): bind immutable provider routing context
Jul 21, 2026
e8dffb1
test(64-09): load canonical providers in merged view harness
Jul 21, 2026
571fe91
test(64-09): refresh background import count fixture
Jul 21, 2026
0a9558d
test(64-09): refresh shipped provider parity matrix
Jul 21, 2026
c231e0d
docs(64-09): complete provider authorization routing
Jul 21, 2026
0a72ded
test(64-10): add failing durable provider lifecycle cases
Jul 21, 2026
dda88ae
feat(64-10): persist canonical provider lifecycle entries
Jul 21, 2026
b710498
test(64-10): add failing concurrent provider controller cases
Jul 21, 2026
013361d
feat(64-10): generalize durable delegation controller
Jul 21, 2026
c2b22e8
test(64-10): add failing per-adapter drift cases
Jul 21, 2026
e3499c6
feat(64-10): isolate safe drift diagnostics by provider
Jul 21, 2026
3548cf3
docs(64-10): complete durable provider lifecycle plan
Jul 21, 2026
468eb07
docs(64-10): synchronize plan tracking
Jul 21, 2026
eb0dc40
test(64-11): add failing OpenCode Providers tests
Jul 21, 2026
1dd56da
feat(64-11): promote OpenCode in Providers logic
Jul 21, 2026
1837519
test(64-11): add failing OpenCode Providers UI tests
Jul 21, 2026
c8d3de8
feat(64-11): load canonical Providers roster
Jul 21, 2026
e66abe7
docs(64-11): complete OpenCode Providers plan
Jul 21, 2026
cba50a3
docs(64-11): synchronize plan tracking
Jul 21, 2026
3624338
test(64-12): pin canonical delegation lifecycle UI
Jul 21, 2026
6174b8b
feat(64-12): data-drive delegation lifecycle labels
Jul 21, 2026
fea07bc
test(64-12): pin feed parity and terminal barrier
Jul 21, 2026
394d919
feat(64-12): gate feed success on terminal truth
Jul 21, 2026
8d4efa1
docs(64-12): complete OpenCode delegated UI plan
Jul 21, 2026
c7f6ddf
docs(64-12): synchronize plan tracking
Jul 21, 2026
2269973
test(64-13): add red UAT honesty contract
Jul 21, 2026
aad446b
docs(64-13): add pending OpenCode UAT ledger
Jul 21, 2026
9971760
test(64-13): add red focused runner contracts
Jul 21, 2026
e14994b
feat(64-13): wire guarded Phase 64 verification
Jul 21, 2026
9eaa482
test(64-13): add red final validation contract
Jul 21, 2026
8b1783a
test(64-13): close Phase 64 validation
Jul 21, 2026
319ff68
docs(64-13): complete OpenCode validation closure
Jul 21, 2026
cd80f88
docs(64-13): synchronize plan tracking
Jul 21, 2026
00d1090
docs(64): add code review report
Jul 21, 2026
9935b7c
fix(64): CR-01 materialize production OpenCode runtimes
Jul 21, 2026
20208cb
fix(64): WR-01 persist OpenCode token metrics
Jul 21, 2026
5dd6e12
fix(64): WR-02 scrub OpenCode provider environment
Jul 21, 2026
122bdd1
fix(64): WR-03 recover policy preflight trees
Jul 21, 2026
206d38b
docs(64): add code review fix report
Jul 21, 2026
933e598
docs(64): record clean code re-review
Jul 21, 2026
d0cc82d
docs(phase-64): add security threat verification
Jul 21, 2026
7eac141
docs(phase-64): add goal verification
Jul 21, 2026
d2149d4
docs(64): UI audit review
Jul 21, 2026
c11eea6
docs(phase-64): complete phase execution
Jul 21, 2026
b5aa29f
docs(phase-64): evolve PROJECT.md after phase completion
Jul 21, 2026
597c543
fix: patch reviewed P1 and P2 defects
Jul 21, 2026
ba8d317
docs(65): capture phase context
Jul 22, 2026
11909a5
docs(65): research Codex adapter
Jul 22, 2026
9d55ed8
docs(65): UI design contract
Jul 22, 2026
3ea9a01
docs(65): add validation strategy
Jul 22, 2026
8aef6f8
docs(65): create verified implementation plans
Jul 22, 2026
6cf12e5
feat(65-01): define accepted agent identity contract
Jul 22, 2026
8fb813a
feat(65-01): persist accepted agent identity
Jul 22, 2026
1b11da2
docs(65-01): complete accepted identity foundation plan
Jul 22, 2026
33ae20c
docs(phase-65): update tracking after wave 1
Jul 22, 2026
4b3e681
feat(65-02): bind exact identity at preflight
Jul 22, 2026
5be9233
feat(65-02): bind exact identity into consent
Jul 22, 2026
ce7ef4c
docs(65-02): complete accepted identity consent plan
Jul 22, 2026
550cf16
docs(phase-65): update tracking after wave 2
Jul 22, 2026
fa8e2a4
feat(65-03): define accepted identity boundary [65-03-01]
Jul 22, 2026
ed9cb63
feat(65-03): bind consent identity to immediate start [65-03-02]
Jul 22, 2026
8f97de5
docs(65-03): record immediate-start identity completion
Jul 22, 2026
8f63e6c
docs(phase-65): update tracking after wave 3
Jul 22, 2026
4dd8c8a
feat(65-04): add sanitized process probe substrate
Jul 22, 2026
21b2725
feat(65-04): bind direct runtime authority
Jul 22, 2026
ee613ad
feat(65-04): enforce direct pre-spawn authority
Jul 22, 2026
8de1d71
docs(65-04): summarize direct runtime authority
Jul 22, 2026
1f653fe
docs(phase-65): update tracking after wave 4
Jul 22, 2026
0a627a2
docs(65): close Codex runtime ownership gap
Jul 22, 2026
4aac3c8
docs(65): include supervisor in atomic Codex gate
Jul 22, 2026
a9258cf
feat(65): add atomic Codex runtime adapter
Jul 22, 2026
c4269db
docs(65): complete atomic Codex adapter plan
Jul 22, 2026
fa94cb4
docs(phase-65): update tracking after wave 5
Jul 22, 2026
a590e1c
docs(65): bind safe auth projection at daemon source
Jul 22, 2026
3334e8f
feat(65-06): bind Codex auth evidence to starts
Jul 22, 2026
8038983
feat(65-06): render safe Codex auth evidence
Jul 22, 2026
48cbd4a
test(65-06): align broad Codex promotion coverage
Jul 22, 2026
cd0c436
docs(65-06): record Codex authority promotion
Jul 22, 2026
59e693d
docs(phase-65): update tracking after wave 6
Jul 22, 2026
382f2d8
feat(65-07): render durable delegated identity
Jul 22, 2026
0ec12c2
fix(65-07): raise delegated action targets
Jul 22, 2026
16029dd
docs(65-07): complete durable delegated UI plan
Jul 22, 2026
65ce907
docs(65-07): record plan completion
Jul 22, 2026
0e5a05f
test(65-08): lock validation and human UAT contracts
Jul 22, 2026
8810e20
test(65): refresh final runtime authority contract
Jul 22, 2026
59f5c2b
test(65): refresh canonical provider sentinels
Jul 22, 2026
a145149
test(65): refresh root provider harnesses
Jul 22, 2026
a674b10
fix(65): retain deterministic provider environment boundary
Jul 22, 2026
66c802f
test(65): refresh canonical client inventory fixtures
Jul 22, 2026
143be25
test(65): refresh terminal ledger authority fixture
Jul 22, 2026
733de01
fix(65): restore temporary dirty artifact rewrites
Jul 22, 2026
68ffaa9
test(65): read deleted planning fixture from HEAD
Jul 22, 2026
e958cd5
test(65-08): wire preservation-safe phase closure gate
Jul 22, 2026
a26b80f
docs(65-08): complete Codex closure gate
Jul 22, 2026
736f065
docs(phase-65): record execution completion
Jul 22, 2026
e1cb840
docs(65): add code review report
Jul 22, 2026
a35b4dd
fix(65): settle bounded probe process trees
Jul 22, 2026
a804277
fix(65): zero probe source buffers
Jul 22, 2026
1528190
fix(65): attest complete Codex native authority
Jul 22, 2026
067464a
fix(65): settle successful probe trees
Jul 22, 2026
42420ba
fix(65): await Codex config response before EOF
Jul 22, 2026
ca5fe54
docs(65): record clean code re-review
Jul 22, 2026
c782ba4
docs(65): add code review fix report
Jul 22, 2026
2b560f9
docs(phase-65): add security threat verification
Jul 22, 2026
a1c6908
docs(65): UI audit review
Jul 22, 2026
7fde3f2
fix(ui): exclude tool payloads from delegation presentation
Jul 22, 2026
4bf359a
fix(ui): preserve closed Codex auth recovery reasons
Jul 22, 2026
7b28225
docs(65): record source-complete UI re-audit
Jul 22, 2026
275d3e7
docs(65): add UI review fix report
Jul 22, 2026
1cdeb84
docs(phase-65): record automated verification
Jul 22, 2026
c092c7b
docs(phase-65): mark human verification pending
Jul 22, 2026
435948e
Merge refinements-v0.9.91 into automation
Jul 23, 2026
6a66ad0
chore: remove archived phase workspaces
Jul 23, 2026
2e9c10c
test: stabilize merged release validation
Jul 23, 2026
fab120f
docs: refresh v0.9.91 crawler metadata
Jul 23, 2026
f56433e
Merge origin/main into automation
Jul 23, 2026
bdad374
fix: harden summary redaction and evidence references
Jul 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
75 changes: 73 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ jobs:
run: npm --prefix showcase/angular install --no-audit --no-fund
- name: Validate extension (manifest + JS syntax)
run: npm run validate:extension
- name: Run extension + bridge contract tests
- name: Phase 65 Codex contract (sole Linux root invocation)
run: npm test

mcp-smoke:
Expand All @@ -47,9 +47,80 @@ jobs:
run: npm --prefix mcp install --no-audit --no-fund
- name: Build MCP server (TypeScript)
run: npm --prefix mcp run build
- name: Phase 62 adapter drift smoke
run: node tests/mcp-agent-drift-smoke.test.js
- name: MCP lifecycle + tools smoke
run: npm run test:mcp-smoke

native-host-windows:
name: native host (Windows PE + pack)
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '20'
- name: Install MCP dependencies
run: npm --prefix mcp ci --no-audit --no-fund
- name: Build x64 native-host bootstrap
shell: cmd
run: |
call "%ProgramFiles%\Microsoft Visual Studio\2022\Enterprise\Common7\Tools\VsDevCmd.bat" -arch=x64 -host_arch=x64
if errorlevel 1 exit /b %errorlevel%
node scripts/build-native-host-windows.mjs --arch x64
- name: Build arm64 native-host bootstrap
shell: cmd
run: |
call "%ProgramFiles%\Microsoft Visual Studio\2022\Enterprise\Common7\Tools\VsDevCmd.bat" -arch=arm64 -host_arch=x64
if errorlevel 1 exit /b %errorlevel%
node scripts/build-native-host-windows.mjs --arch arm64
- name: Verify both PE artifacts and write package metadata
shell: cmd
run: |
call "%ProgramFiles%\Microsoft Visual Studio\2022\Enterprise\Common7\Tools\VsDevCmd.bat" -arch=x64 -host_arch=x64
if errorlevel 1 exit /b %errorlevel%
node scripts/build-native-host-windows.mjs --arch all --verify-only --metadata-out mcp/native-host/windows-artifacts.json
- name: Execute the x64 bootstrap and safe registry-helper harnesses
run: node tests/mcp-native-host-packaging.test.js --section windows-bootstrap
- name: Inspect the staged npm package
working-directory: mcp
run: npm pack --dry-run --ignore-scripts --json
- name: Read package version
id: package-version
shell: pwsh
run: |
node -e "require('fs').appendFileSync(process.env.GITHUB_OUTPUT, 'version=' + require('./mcp/package.json').version + String.fromCharCode(10))"
- name: Upload version-bound Windows bootstrap artifacts
uses: actions/upload-artifact@v4
with:
name: fsb-native-host-${{ steps.package-version.outputs.version }}
if-no-files-found: error
path: |
mcp/native-host/bin/win32-x64/fsb-native-host.exe
mcp/native-host/bin/win32-x64/fsb-native-host-registry.exe
mcp/native-host/bin/win32-arm64/fsb-native-host.exe
mcp/native-host/bin/win32-arm64/fsb-native-host-registry.exe
mcp/native-host/windows-artifacts.json

runtime-payload:
name: native runtime payload (${{ matrix.os }})
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '20'
- name: Install MCP dependencies from the committed lock
run: npm --prefix mcp ci --no-audit --no-fund
- name: Build the package payload
run: npm --prefix mcp run build
- name: Prove complete offline payload and negative cases
run: node tests/mcp-native-host-packaging.test.js --section workflow-and-pack

website:
name: showcase (build + crawler smoke)
runs-on: ubuntu-latest
Expand Down Expand Up @@ -88,7 +159,7 @@ jobs:

all-green:
name: all-green
needs: [extension, mcp-smoke, website]
needs: [extension, mcp-smoke, website, native-host-windows, runtime-payload]
runs-on: ubuntu-latest
steps:
- run: echo "All required CI checks passed."
154 changes: 135 additions & 19 deletions .github/workflows/npm-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,20 +4,65 @@ on:
push:
tags:
# Only mcp release tags trigger npm publish. Repo-wide milestone
# tags (v0.9.x) are markers, not publishable artifacts; including them
# caused every milestone tag to fail npm-publish (re-publishing an
# existing mcp version).
# tags are markers, not publishable artifacts.
- 'mcp-v*'
workflow_dispatch:

jobs:
windows-bootstrap:
name: build native-host Windows artifacts
runs-on: windows-latest
outputs:
version: ${{ steps.package-version.outputs.version }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '20'
- name: Install MCP dependencies
run: npm --prefix mcp ci --no-audit --no-fund
- name: Build x64 native-host bootstrap
shell: cmd
run: |
call "%ProgramFiles%\Microsoft Visual Studio\2022\Enterprise\Common7\Tools\VsDevCmd.bat" -arch=x64 -host_arch=x64
if errorlevel 1 exit /b %errorlevel%
node scripts/build-native-host-windows.mjs --arch x64
- name: Build arm64 native-host bootstrap
shell: cmd
run: |
call "%ProgramFiles%\Microsoft Visual Studio\2022\Enterprise\Common7\Tools\VsDevCmd.bat" -arch=arm64 -host_arch=x64
if errorlevel 1 exit /b %errorlevel%
node scripts/build-native-host-windows.mjs --arch arm64
- name: Verify PE architecture, embedded version, and checksums
shell: cmd
run: |
call "%ProgramFiles%\Microsoft Visual Studio\2022\Enterprise\Common7\Tools\VsDevCmd.bat" -arch=x64 -host_arch=x64
if errorlevel 1 exit /b %errorlevel%
node scripts/build-native-host-windows.mjs --arch all --verify-only --metadata-out mcp/native-host/windows-artifacts.json
- name: Execute x64 bootstrap and safe registry-helper contract harnesses
run: node tests/mcp-native-host-packaging.test.js --section windows-bootstrap
- name: Read package version
id: package-version
shell: pwsh
run: |
node -e "require('fs').appendFileSync(process.env.GITHUB_OUTPUT, 'version=' + require('./mcp/package.json').version + String.fromCharCode(10))"
- name: Upload version-bound bootstrap payload
uses: actions/upload-artifact@v4
with:
name: fsb-native-host-${{ steps.package-version.outputs.version }}
if-no-files-found: error
path: |
mcp/native-host/bin/win32-x64/fsb-native-host.exe
mcp/native-host/bin/win32-x64/fsb-native-host-registry.exe
mcp/native-host/bin/win32-arm64/fsb-native-host.exe
mcp/native-host/bin/win32-arm64/fsb-native-host-registry.exe
mcp/native-host/windows-artifacts.json

publish:
needs: windows-bootstrap
runs-on: ubuntu-latest
permissions:
contents: write
defaults:
run:
working-directory: mcp
steps:
- uses: actions/checkout@v4

Expand All @@ -26,36 +71,107 @@ jobs:
node-version: '20'
registry-url: 'https://registry.npmjs.org'

- run: npm ci
- run: npm run build

- name: Publish to npm
run: npm publish --access public
- name: Install exact MCP dependency tree
run: npm --prefix mcp ci --no-audit --no-fund
- name: Build MCP package
run: npm --prefix mcp run build
- name: Download version-bound Windows bootstrap payload
uses: actions/download-artifact@v4
with:
name: fsb-native-host-${{ needs.windows-bootstrap.outputs.version }}
path: mcp/native-host
- name: Verify release tag and package version binding
if: github.event_name == 'push'
run: test "$GITHUB_REF_NAME" = "mcp-v${{ needs.windows-bootstrap.outputs.version }}"
- name: Pack the exact verified payload once
id: pack
working-directory: mcp
run: |
mkdir -p "$RUNNER_TEMP/fsb-npm-pack"
npm pack . --ignore-scripts --json --pack-destination "$RUNNER_TEMP/fsb-npm-pack" > "$RUNNER_TEMP/fsb-pack-receipt.json"
node -e "const fs=require('fs');const path=require('path');const r=require(process.env.RUNNER_TEMP+'/fsb-pack-receipt.json')[0];fs.appendFileSync(process.env.GITHUB_OUTPUT,'tarball='+path.resolve(process.env.RUNNER_TEMP,'fsb-npm-pack',r.filename)+String.fromCharCode(10))"
- name: Verify final tarball PE files, receipt, complete bundle, and offline negatives
run: node tests/mcp-native-host-packaging.test.js --section workflow-and-pack
env:
FSB_REQUIRE_REAL_WINDOWS_ARTIFACTS: '1'
FSB_PACKED_TARBALL: ${{ steps.pack.outputs.tarball }}
- name: Bind tarball, lock, receipt, and PE checksums
id: release-metadata
env:
TARBALL: ${{ steps.pack.outputs.tarball }}
run: |
node <<'NODE'
const { createHash } = require('crypto');
const { mkdirSync, readFileSync, writeFileSync, appendFileSync } = require('fs');
const { basename, join } = require('path');
const hash = (algorithm, bytes) => createHash(algorithm).update(bytes).digest('hex');
const packageManifest = require('./mcp/package.json');
const lockBytes = readFileSync('./mcp/package-lock.json');
const receiptBytes = readFileSync('./mcp/native-host/runtime-integrity.json');
const receipt = JSON.parse(receiptBytes);
const windows = require('./mcp/native-host/windows-artifacts.json');
if (windows.version !== packageManifest.version || windows.package !== packageManifest.name) {
throw new Error('Windows metadata package/version mismatch');
}
const lockSha256 = hash('sha256', lockBytes);
if (receipt.lockSha256 !== lockSha256) throw new Error('runtime receipt lock mismatch');
const tarballBytes = readFileSync(process.env.TARBALL);
const metadata = {
schema: 1,
packageName: packageManifest.name,
packageVersion: packageManifest.version,
tarball: basename(process.env.TARBALL),
tarballBytes: tarballBytes.length,
tarballSha512: hash('sha512', tarballBytes),
lockSha256,
integrityReceiptSha256: hash('sha256', receiptBytes),
peArtifacts: windows.artifacts.map(({ architecture, role, path, bytes, peMachine, sha256, packageVersion, roleMarker }) => ({
architecture,
role,
path,
bytes,
peMachine,
sha256,
packageVersion,
roleMarker,
})),
};
const directory = join(process.env.RUNNER_TEMP, 'fsb-release-metadata');
const pathname = join(directory, `fsb-mcp-server-${packageManifest.version}-release-metadata.json`);
mkdirSync(directory, { recursive: true });
writeFileSync(pathname, `${JSON.stringify(metadata, null, 2)}\n`);
appendFileSync(process.env.GITHUB_OUTPUT, `metadata=${pathname}\n`);
NODE
- name: Upload version-keyed release integrity metadata
uses: actions/upload-artifact@v4
with:
name: fsb-mcp-release-metadata-${{ needs.windows-bootstrap.outputs.version }}
if-no-files-found: error
path: ${{ steps.release-metadata.outputs.metadata }}
- name: Publish the already-verified tarball to npm
run: npm publish "${{ steps.pack.outputs.tarball }}" --access public
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}

- name: Extract version
id: version
run: echo "version=$(node -p 'require("./package.json").version')" >> $GITHUB_OUTPUT

- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
name: "fsb-mcp-server v${{ steps.version.outputs.version }}"
name: "fsb-mcp-server v${{ needs.windows-bootstrap.outputs.version }}"
body: |
## Install / Update

```bash
npx -y fsb-mcp-server@${{ steps.version.outputs.version }}
npx -y fsb-mcp-server@${{ needs.windows-bootstrap.outputs.version }}
```

Or install globally:
```bash
npm i -g fsb-mcp-server@${{ steps.version.outputs.version }}
npm i -g fsb-mcp-server@${{ needs.windows-bootstrap.outputs.version }}
```

Install into MCP clients:
```bash
npx fsb-mcp-server install --all
```
files: |
${{ steps.release-metadata.outputs.metadata }}
generate_release_notes: true
Loading
Loading