Skip to content

fix: Windows source packing false positives, release 0.1.15 - #329

Merged
Fermionic-Lyu merged 1 commit into
mainfrom
fix/windows-source-pack
Oct 1, 2026
Merged

Fermionic-Lyu merged 1 commit into
mainfrom
fix/windows-source-pack

Conversation

@Fermionic-Lyu

@Fermionic-Lyu Fermionic-Lyu commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Windows source deploys can fail with .dockerignore changed while packing even when the file is unchanged: some libuv versions report lstat.dev = 0 while fstat.dev contains the volume ID. Treat the walk's zero device ID as unavailable on Windows, while retaining file type, inode, size, and known-device mismatch checks. POSIX device comparisons remain strict.

Prepare CLI 0.1.15; the separate template PR #327 already reserves 0.1.14.

Validation:

  • Reproduced the original packing error before the fix; both zero-device regression cases then passed.
  • Typecheck, build, and all 1,949 tests pass (95 files).
  • Independent mutation checks verified Windows-only scope and preservation of device, inode, and size guards.
  • No formatter or linter is configured; git diff --check passes.

Ticket: https://linear.app/insforge/issue/SUP2-122/windows-source-deploy-falsely-detects-changed-files


Summary by cubic

Fixes Windows source deploys that falsely failed with .dockerignore changed while packing even when the file was unchanged, and releases CLI 0.1.15 (resolves SUP2-122).

  • Some libuv versions report lstat.dev = 0 while fstat carries the volume ID; the device check is now skipped only when the walk's device is zero on Windows.
  • File type, inode, and size checks still apply on Windows, and POSIX device comparisons remain strict.
  • Adds tests for zero devices, POSIX rejection, known device mismatches, and inode/size guards.

Written for commit d941c10. Summary will update on new commits.

Review in cubic

@agent-zhang-beihai agent-zhang-beihai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed by Wang Miao

This PR loosens the Windows check in readEntry so it no longer refuses unchanged files: when the walk's lstat reports device 0 on win32, the device comparison is skipped, but inode and size still have to match. It also bumps the CLI to 0.1.15. The guard is narrow: it only applies on win32 with a device of exactly 0/0n, and the new tests cover both directions on Windows and confirm Linux and macOS still refuse a mismatched device. I found no defects, so I'm approving.

No findings.

I couldn't run the tests or the typecheck because dependencies aren't installed in the checkout and I didn't install them. I also couldn't confirm the claim behind the fix, that some Windows libuv versions return device 0 from lstat; only a Windows machine would show that. The version jumps from 0.1.13 to 0.1.15 because 0.1.14 is already used on the unmerged feat/template-runtime-fields branch.

@agent-zhang-beihai agent-zhang-beihai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed by Yang Dong

This makes missing Windows device IDs non-fatal and bumps the release version. I would not merge it yet: supported Windows runtimes can also report different nonzero device IDs for the same file, so source deployment still fails there.

Nonzero Windows device-ID inconsistencies still reject unchanged files

important · defect · correctness · src/pack.ts:166

The bypass applies only when lstat reports zero. Windows libuv 1.49–1.50 can instead return differing nonzero representations from path-based lstat and handle-based fstat; upstream commit 82cdfb7 fixed this by making both use the low part of the volume serial. Because the package supports Node 18 and later, affected Node 22 releases remain valid installations and will abort every source pack as “changed while packing.” On Windows, omit the device comparison while retaining inode and size, or canonicalize both device values before comparing them.

Evidence

read-the-code — src/pack.ts:146-169, test/pack.test.ts:538-563, package.json:29-30, upstream libuv src/win/fs.c:1788-1842 at commit 82cdfb7

@Fermionic-Lyu

Copy link
Copy Markdown
Member Author

Yang Dong's nonzero-device finding is a pre-existing case outside this ticket's observed failure: SUP2-122 explicitly reports lstat.dev = 0 with matching inode and size. At base f9af3d8, readEntry already rejects differing nonzero device IDs; this PR leaves that branch unchanged and fixes the reported missing-device case.

Declining the broader bypass here: omitting every Windows device comparison would also stop rejecting known cross-volume identity mismatches. The current regression tests retain that guard and verify the zero-device exception cannot bypass inode or size checks. Upstream's low-part normalization addresses a different representation mismatch and is not required for the reported zero-device case.

Validation on head d941c10: Linux and Windows CI pass, and the local typecheck, build, and all 1,949 tests pass. Independent mutation review confirms the Windows, zero-device, inode, and size restrictions are tested.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread package.json
Comment thread test/pack.test.ts
Comment thread src/pack.ts

@jwfing jwfing left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM - approved.

@Fermionic-Lyu
Fermionic-Lyu merged commit 65fa99c into main Oct 1, 2026
3 checks passed
@Fermionic-Lyu

Copy link
Copy Markdown
Member Author

Post-merge CI: Windows passed. Linux had one failure in the pre-existing SSH stale-lock contention test (test/ssh-orchestration.test.ts:1205, overlapping contenders). The SSH test and implementation are unchanged by this release; the same merged commit passed all 1,949 tests locally. Re-running the failed Linux job; source-packing tests passed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants