Skip to content

fix(release): run SEA build through vp exec - #20

Merged
nullStack65 merged 2 commits into
mainfrom
fix/fork-release-sea-node-exec-20261002
Oct 7, 2026
Merged

nullStack65 merged 2 commits into
mainfrom
fix/fork-release-sea-node-exec-20261002

Conversation

@nullStack65

Copy link
Copy Markdown
Owner

The candidate Linux SEA step used vp run --filter t3 exec, which Vite+ parsed as a missing task and stopped before the build.

This changes the version proof and build-exe invocation to the supported vp exec --filter t3 -- ... surface, keeping both under VP_NODE_VERSION 26.8.2. A focused offline workflow contract test rejects the invalid task form and ambient SEA build.

Verification:

  • vp test run scripts/lib/fork-release-workflow.test.ts (11 passed)
  • vp fmt --check .github/workflows/fork-release.yml scripts/lib/fork-release-workflow.test.ts
  • vp lint scripts/lib/fork-release-workflow.test.ts
  • actionlint -ignore SC2016 -ignore SC2035 .github/workflows/fork-release.yml
  • git diff --check

No release workflow was dispatched or rerun.

Implemented by GPT-5.6-Luna in T3 Code.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Repository: nullStack65/t3code/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2ac8bbe5-ff7a-4b4c-8a2b-48886596a8a4
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nullStack65

Copy link
Copy Markdown
Owner Author

Implementation and verification result:

  • Fixed .github/workflows/fork-release.yml to use vp exec --filter t3 -- ... for the Node version proof, guard, and scripts/cli.ts build-exe --verbose, so the effective SEA build remains under the pinned VP_NODE_VERSION=26.8.2 toolchain.
  • Added an offline contract test that requires the supported commands and rejects both vp run --filter t3 exec -- and the ambient node apps/server/scripts/cli.ts build-exe --verbose boundary.
  • vp test run scripts/lib/fork-release-workflow.test.ts: 1 file, 11 tests passed.
  • vp fmt --check and targeted vp lint: passed.
  • actionlint current vs base: both report only the same pre-existing SC2016/SC2035 ShellCheck notices; actionlint passes with those baseline notices ignored.
  • git diff --check: passed.

No release workflow was dispatched or rerun; no candidate was published or installed. Remaining risk is limited to the hosted runner executing the pinned toolchain/build and normal PR CI; this PR does not alter publication, receipt, signing, asset, or native acceptance gates.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:XS labels Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 13.5 KiB 13.5 KiB +29 B (+0.2%) 15.1 KiB ✅
Codex Thread snapshot wire 7.1 KiB 7.1 KiB −1 B (−0.0%) 7.3 KiB ✅
Codex Live turn WebSocket wire 6.4 KiB 6.5 KiB +30 B (+0.5%) 7.8 KiB ✅
Codex Live turn WebSocket decoded 56.2 KiB 56.3 KiB +44 B (+0.1%) 66.4 KiB ✅
Codex Live turn messages 9 10 +1 (+11.1%) 21 ✅
Claude Total thread wire 13.5 KiB 13.5 KiB −17 B (−0.1%) 15.1 KiB ✅
Claude Thread snapshot wire 7.1 KiB 7.1 KiB −7 B (−0.1%) 7.3 KiB ✅
Claude Live turn WebSocket wire 6.5 KiB 6.4 KiB −10 B (−0.2%) 7.8 KiB ✅
Claude Live turn WebSocket decoded 57.0 KiB 57.0 KiB 0 B (0.0%) 66.4 KiB ✅
Claude Live turn messages 9 9 0 (0.0%) 21 ✅

Baseline: 170c0fa · PR result: 89cf6ae · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 113.9 KiB
  • Claude decoded thread snapshot: 114.6 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@nullStack65

Copy link
Copy Markdown
Owner Author

NON-VOTING TECHNICAL REVIEW — PR20

Verdict: TECHNICAL PASS WITH RESIDUALS

Repository: nullStack65/t3code
PR: 20
Exact head reviewed: 81205a9f0b335244b50a677d8d6024323dc3ceef
Exact base reviewed: 23467c599a401b7a5baf3c7052f0d45a181bc278
Worktree: /Users/businessaccount/.local/share/delivery-workspaces/t3-pr20-owner-only-review-20261002
Scope: whole two-file diff and release-safety review; read-only, explicitly non-voting.

Findings, ordered by severity

None — no release-safety defect found in the reviewed diff

  • The only workflow change is in cli_linux_x64: all three relevant operations now use the supported vp exec --filter t3 -- ... form: the version probe, the Node minimum-version guard, and the actual scripts/cli.ts build-exe --verbose invocation.
  • No vp run --filter t3 exec -- remains in the workflow. The direct ambient invocation node apps/server/scripts/cli.ts build-exe --verbose is also removed.
  • VP_NODE_VERSION: "26.8.2" matches SEA_NODE_VERSION = "26.8.2" in apps/server/vite.config.ts. The proof and build both run through vp exec under the same package-filtered toolchain boundary; the guard fails below Node 25.7, which is the required --build-sea floor.
  • The added focused test rejects both regressions: the old task-shaped vp run --filter t3 exec -- command and the ambient/direct build command. It also asserts the pinned version and all three vp exec forms.
  • The diff leaves publication, no-overwrite/concurrency, signing, receipt, required-reviewer environment, and native-qualification gates unchanged. Publication still promotes a downloaded candidate by run ID and does not rebuild; native receipts remain required for promotion.
  • Shell quoting is intentional: the single-quoted node -e program protects JavaScript template literals and ${process.versions.node} from Bash expansion. The changed block passes bash -n. GitHub expression syntax is not embedded in that JavaScript snippet.

Low — verification residual, environment-only

  • vp test run scripts/lib/fork-release-workflow.test.ts could not start because this detached worktree has no project-local Vite+ installation (vite-plus unresolved). No dependency installation was performed, per the read-only/offline scope.
  • actionlint .github/workflows/fork-release.yml reports SC2016/SC2035 informational shellcheck findings. The same findings and line locations exist on the exact base; with those pre-existing findings ignored, actionlint exits successfully. They are not introduced by PR20.

Commands run

  • git rev-parse HEAD
  • git rev-parse 23467c599a401b7a5baf3c7052f0d45a181bc278
  • git diff --stat, git diff --name-status, and full two-file git diff --unified=80
  • git diff --check 23467c599a401b7a5baf3c7052f0d45a181bc278 81205a9f0b335244b50a677d8d6024323dc3ceef
  • git grep for old/new Vite+ invocation forms and release-gate terms
  • vp test run scripts/lib/fork-release-workflow.test.ts (blocked by missing local dependency; no test execution)
  • actionlint .github/workflows/fork-release.yml (base-equivalent SC2016/SC2035 findings)
  • actionlint -ignore 'SC2016|SC2035' .github/workflows/fork-release.yml (pass)
  • sed -n '324,337p' .github/workflows/fork-release.yml | bash -n (pass)

Limits and gate status

No CI or release workflow was rerun. No release, signing, publication, artifact installation, GitHub review API, reviewer assignment, merge, commit, push, or host/provider state change was performed. Current automated checks were treated as context only, not as the human gate. This is a technical result, not human approval.

User human review is still required before merge.

@nullStack65

Copy link
Copy Markdown
Owner Author

START — delivery ownership transferred to the user-approved GPT-6.1 Sol lane. Verifying exact head 81205a9f0b335244b50a677d8d6024323dc3ceef against current base 23467c599a401b7a5baf3c7052f0d45a181bc278; adopting the existing fix, tests and technical review. Fresh independent GPT-6 Luna review is read-only. Existing normal exact-head CI is successful; conditional skipped jobs remain skipped. Release run 36966772441 confirms the original Task "exec" not found failure. No human reviewer requests. Release candidate/install acceptance will remain separately recorded.

@nullStack65

Copy link
Copy Markdown
Owner Author

RESULT — PR #20, REQ-065
Exact head: 81205a9
Exact base: 23467c5
Source unchanged; last hosting refresh OPEN/CLEAN. Existing exact-head normal CI succeeds. Conditional skips are not passes. No branch protection/branch rules returned; historical non-voting technical review preserved.
Independent GPT-6 Luna review collected. Its initial hosted Node-pin defect was withdrawn: local system-first global Vite+1.0.0-rc.0 probe differs from pinned setup-vp managed shim/local0.3.3. No confirmed source defect. Runtime proof of Node26.8.2 remains a real-release acceptance residual. Package cwd supports scripts/cli.ts.
Static checks: diff-check and actionlint pass (unchanged baseline SC2016/SC2035 ignored); targeted format passes. Focused local tests never executed: sparse dependencies then ENOSPC; original exact-head CI and prior 11-test receipt retained. Lint initially lacked sparse plugin; no false PASS.
Resource boundary: shared disk fell from2.2GiB to~116-192MiB; no new dependency installation or heavy build. Reused existing cache via ignored local dependency links only. No source push, merge, release dispatch/publication, install or live service effect.
Custody/return: prior ENV snapshot ready/no active turn; HANDOFF-ENV absent. Existing native HTTP reads timed out10/45sec. Exact ROOT command b19dfdcd-6062-44bb-8c25-1a99220c4d63 saved/readback inside STATUS.json; native dispatch timed out, acceptance UNKNOWN. No changed retry and no fabricated wake. All local processes/child results collected.
Next boundary: restore shared disk floor and native readback; reconcile ENV custody and serialize shared T3 landing. Then ordinary eligible merge and qualified release source manifest including PR21, actual pinned-Node candidate build, native receipts/install/smoke and compatible version rollback coordinated with ENV/Fleet. Existing fork v0.0.43 release is not evidence of this patch being installed; later0.0.44 candidate lacks PR21. Operational acceptance remains open.
Owner: b21b0d5d-5b1b-45af-aea3-a3c4ca83c933; parent ROOT56865c51-a003-4b7d-9d42-05aadb745869.
Verification/delivery: GPT-6.1 Sol, native Codex subscription; independent GPT-6 Luna. No human reviewer requests.

@nullStack65
nullStack65 merged commit eb5d08c into main Oct 7, 2026
18 checks passed
@nullStack65

Copy link
Copy Markdown
Owner Author

PR #20 merged by ordinary squash at eb5d08c (2026-10-07 12:10:04Z). Reviewed/published candidate89cf6aed against live main170c0fab preserves PR21 and docs23. Independent GPT-6 Luna review: no findings; earlier local-runtime claim withdrawn after environment challenge. Normal exact-head CI37617421182 SUCCESS; focused11 tests pass; targeted lint/actionlint/diff checks pass; conditional skips retained.

Candidate-only fork release37619216463 builds v0.0.44 from exact merged SHA; publish=false. Postmerge CI37619085562 also in progress. No publication, install, live service mutation or operational acceptance yet. Candidate build must prove SEA Node26.8.2 and all required platform assets. Final release source manifest/native receipts/frozen candidate digest and existing owner-only environment gate remain required; coordinate live effects with ENV/Fleet and other T3 owners. Last published v0.0.43 is separate from this patch. No backups or destructive recovery.

ROOT milestone delivered via native command with saved immutable body and exact readback, sequence1046005. All Luna children collected; foreground GitHub watcher handles retained in STATUS.json. Earlier capacity/native failures are historical; disk7.5GiB and native route now recovered. User human reviewer only; no reviewer requests. Delivery GPT-6.1 Sol, independent GPT-6 Luna, native Codex subscription.

Copy link
Copy Markdown
Owner Author

Cloud delivery RESULT — postmerge/release qualification refresh (non-voting)

PR20 remains merged at eb5d08c3143d94d9b672f75ab2b9f336581cc07f; no reopen, new PR, branch publication or merge replay. Clean cloud checkout adopted the merged source and current main eca73bdf0edf9265eea299c7513a5ab08a7411b7 (includes PR22). Exact supplied PR-head object is absent locally; Git fetch fails connecting to configured proxy port 8080. Connected GitHub readback confirms supplied head 89cf6aed514515a2721db8698a549c22d525bcdc and merge. No WIP is present. Release files are identical between PR20 merge and current base; current-base focused workflow contract: 11/11 passed.

Live hosted evidence: PR20 postmerge CI 37619085562 SUCCESS; current-base CI 37620644260 SUCCESS. Provisional candidate 37619216463, source eb5d08c, completed FAILURE: Linux SEA/archive smoke/provenance SUCCESS, macOS x64 packaging SUCCESS, Windows x64 installer/CLI packaging and archive smoke SUCCESS; qualification's Linux and embedded WSL verification SUCCESS. ARM64 was SKIPPED. Qualification job 112791315275 failed at freeze: Intel macOS DMG has no readable packaged provenance after 7-Zip reported an ignored /Applications link. That log does not establish link handling as the provenance root cause. No frozen candidate/identity artifact was uploaded; promotion and receipts were skipped. Candidate also predates PR22 and cannot be final.

Independent native Luna read-only review confirms digest-bound packaged inspection, final manifest/checksums, native Windows/WSL and Intel Mac receipts, and rollback compatibility remain required. Refreshed peer source: PR21 and PR22 merged; PR7/10/11/13 remain open and are not silently qualified/waived.

Unavailable boundaries: cloud gh reports invalid configured GH_TOKEN; shell fetch cannot reach proxy; connected GitHub tools permit evidence/comment reads/writes but expose no workflow-dispatch tool. Existing Desktop Commander device inventory exposes only Crown-Rain-Gutters.local (Mac), no Windows host. No Mac workers/builds, host mutation, new credentials/grants, or production-data access were performed.

Exact next actions: freeze the final landed-source manifest including PR22 and qualified peer requirements; produce digest-bound DMG inspection through the existing verifier (--targets mac --emit-inspection) and deliver it to qualification; build/qualify that exact final source via authorized workflow dispatch; perform artifact-bound native/platform and peer synthetic runtime acceptance on existing authorized hosts; establish known data-compatible version/config rollback without backups; import bound receipts, then ordinary gated promotion of frozen bytes. Source landing is complete; release publication and installed operational acceptance remain BLOCKED, not passed. Durable cloud STATUS/RESULT retained. No callbacks or review requests/votes.

Model/harness: native Codex delivery owner with bounded gpt-6-luna independent review/investigation.

Copy link
Copy Markdown
Owner Author

Targeted continuation — repair implemented and published as ordinary successor PR #24, exact head 7a0c6139fd5806379b399b8899d460cfa35aa120, base 404501a06b52fe7cc06d93ec5879ee72e3bf3bfc. No duplicate repair was found among fresh open PRs/remote branches. PR11 has now merged; refreshed #7/#10/#11/#13/#22 receipts and synthetic acceptance requirements are retained in this cloud task.

Minimal required Intel x64 correction: opt-in native Mac inspection emits digest-bound evidence beside the DMG for the existing desktop artifact/qualify path. A nonnative extraction failure is unavailable inspection rather than authoritative unreadable provenance, permitting only exact-digest native evidence to fill it. Missing/stale evidence, readable invalid metadata and explicit native unreadable results still fail closed. Optional ARM64 remains disabled/unqualified. Publication/native/signing/checksum gates unchanged.

Luna implementation and distinct Luna review complete; 30 focused workflow/inspector/manifest tests, targeted lint, changed-file formatting and diff check passed. Published one five-file commit on refreshed current main; normal CI and eligible landing in progress. This supersedes the earlier source-gap boundary: narrow successor source repair is now authorized and implemented. Release remains incomplete pending landed repair, exact final candidate dispatch/qualification, existing-host synthetic/native acceptance and data-compatible rollback; no host workers, provisional install, callbacks or waivers.

Copy link
Copy Markdown
Owner Author

Source repair landed — ordinary successor PR24 squash merge cb9636bfede88938f4b2358ba439884c52760b4e, single parent 404501a06b52fe7cc06d93ec5879ee72e3bf3bfc. Landed tree 4b6973cd81a58ec85ec93938c072f31243377889 exactly matches qualified head 47e9cc1d00929a7ad18cc3001ddd80592e827b11. Fresh current-base/head checks, clean mergeability and zero unresolved discussions verified immediately before exact-head guarded ordinary merge; no admin/bypass, settings changes, branch deletion, force push or human vote.

Final-head CI37633977181 and fingerprint37633977169 SUCCESS. The initial Check's new-test TS377057 fixture diagnostics were corrected, reviewed and superseded by passing exact-head CI, not waived. 30 focused tests, scripts scoped typecheck, targeted lint/format/whitespace and YAML parse passed. Distinct Luna implementation/review found no Intel blocker. Required Intel DMG evidence emission/consumption and failed nonnative extraction handling are repaired while missing/stale proof and native failure remain fail-closed. ARM64 stays disabled/unqualified.

Frozen source selection for the next candidate: cb9636bfede88938f4b2358ba439884c52760b4e includes PR20/21/22/7/10/13/11 and this repair. Proposed Fork release dispatch: workflow revision main containing PR24; sha=that exact merge; version=0.0.44; upstream_base=0.0.42; publish=false; include_macos_arm64=false. Recheck current latest published version before dispatch (currently v0.0.43). No frozen artifact manifest/digest is claimed yet. Postmerge CI is being collected.

Remaining concrete gates: dispatch and qualify final candidate; confirm emitted digest-bound Mac inspection alongside DMG and candidate identity/checksums; existing-host native Mac and Windows/WSL acceptance plus recorded peer synthetic requirements (PR7 quiet/resume/terminal delivery, PR10 SCM lifecycle/owned descendants, PR11 launch-preflight/cwd delivery, PR13 resume-identity/history guard, PR22 owner-only routing with no real notifications); compatible version/config rollback without backups; real bound receipts and gated promotion of the same accepted bytes.

Unavailable capability remains real: no supported workflow-dispatch tool; cloud shell proxy unavailable/configured gh token invalid; authorized Desktop Commander discovery exposes only the Mac, no Windows device. No Mac workers/builds/host restart, provisional install, data copy or new credential/grant. Receipt import must also have a concrete authorized ingress for fork-native-receipts.json (current selected-source-root requirement), not an invented upload. Durable source/peer/action records retained in this cloud task; no callbacks.

Copy link
Copy Markdown
Owner Author

Targeted continuation RESULT — repair source and landing complete

Successor PR24 is merged at cb9636bfede88938f4b2358ba439884c52760b4e (parent 404501a06b52fe7cc06d93ec5879ee72e3bf3bfc), preserving linear main. Its tree exactly matches tested/reviewed head 47e9cc1d00929a7ad18cc3001ddd80592e827b11; all five changed files verified after landing. Final-head CI37633977181 and fingerprint37633977169 passed. Postmerge CI37635278267 completed SUCCESS: Check/typecheck/desktop build, Test, all three server shards, Rust and Release Smoke passed; conditional native analysis skipped. Distinct Luna implementation/review and 30 focused tests passed. No bypass/force/settings/branch deletion/human vote or callback.

The required Intel Mac job now emits inspection evidence bound to the exact DMG digest and carries it into the existing qualification path. Failed nonnative extraction is unavailable inspection, requiring matching native proof; missing/stale evidence, invalid metadata and authoritative native inspection failures still block. Generic reusable callers default off. ARM64 remains disabled/unqualified.

Final source selection: cb9636bfede88938f4b2358ba439884c52760b4e, containing #20/#21/#22/#7/#10/#13/#11 plus #24. Build via Fork release at a workflow revision containing #24, inputs sha=that exact SHA, version=0.0.44, upstream_base=0.0.42, publish=false, include_macos_arm64=false. Current latest published fork remains v0.0.43; preflight must recheck version ordering at actual dispatch. Confirm native Mac evidence emission, exact-source/platform provenance, embedded WSL equality, frozen manifest/checksums/candidate identity and qualifying artifact upload. The old eb5d08c candidate failed and cannot substitute for this final source.

Then execute existing-host artifact-bound Mac and Windows/WSL acceptance and each merged peer's synthetic gates, recording exact installers/runtime digests, version/source, host/platform, adapter-call counts/denials and actual outcomes. No real reviewer notifications/votes. Preserve version/config rollback with known data compatibility; backward compatibility with old shared-schema/runtime remains unqualified, and backups are prohibited. Supply real digest-bound native receipts through a concrete authorized ingress (current import job requires fork-native-receipts.json in the selected source root), validate/import against the frozen candidate, then promote the same accepted bytes through fork-release's owner gate. Receipt ingestion must not be invented or bypassed.

Unavailable capabilities: no supported workflow-dispatch tool; cloud gh reports invalid configured token and shell fetch cannot connect to configured proxy; authorized device discovery exposes only existing Mac, no Windows host. No Mac workers/builds/host restart, provisional install, production-data copy, credentials/grants changes or unattended wake capability. Artifact manifest/digests, installed acceptance and publication are still absent—not passed. This is the remaining capability boundary after completing the repairable source work.

Durable cloud STATUS, RESULT, landed-source selection, peer acceptance receipts and exact next actions are retained under /workspace/work/pr20. PR20 remains the single shared release owner record; no other lane/controller callbacks. Source complete; shared release outcome still incomplete.

Copy link
Copy Markdown
Owner Author

Release continuation after LAN correction: PR24 merge cb9636b and postmerge CI37635278267 remain green. Existing authorized management Mac authenticated as nullStack65 and dispatched exactly one nonpublishing 0.0.44 candidate at that exact source: https://github.com/nullStack65/t3code/actions/runs/37639312564 (upstream_base0.0.42, ARM false). Intel Mac job112855241500 passed packaging AND native digest-bound provenance inspection/upload, confirming PR24 in hosted execution. Linux job112855241048 built SEA under pinned Node26.8.2 but archive --version smoke failed MODULE_NOT_FOUND './impl/format'; provenance/upload, Windows packaging, aggregate qualification and promotion correctly did not proceed. No install/publication. A sole Luna cloud implementation is investigating the jsonc-parser3.3.1 UMD bundling edge; separate review and normal CI will precede any successor landing.

Fresh bounded strict host discovery: R720 root@192.168.5.1 and ASUS dev@192.168.6.250 denied authentication; laptop documented identity/pinned known-host file unavailable; ARC ubuntu@192.168.5.40 rejected changed host key. No key copying, trust bypass, restart or grants. TCP reachability does not establish native Windows acceptance. Dispatch capability is restored through existing Mac gh keyring; this supersedes the earlier dispatch-unavailable record. Windows authenticated host/receipt ingress and known-compatible rollback acceptance remain outstanding.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XS vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant