Skip to content

fix(release): verify installed registry package manifests - #165

Merged
Grivn merged 1 commit into
mainfrom
codex/fix-rc-release-verifier
Sep 3, 2026
Merged

fix(release): verify installed registry package manifests#165
Grivn merged 1 commit into
mainfrom
codex/fix-rc-release-verifier

Conversation

@Grivn

@Grivn Grivn commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

摘要 / Summary

修正 RC 发布流水线在 Registry 插件安装完成后从错误对象层级读取包名的问题,并补充真实创建 node_modules/<package>/package.json 的回归测试。该修复只涉及仓库发布工具与测试,不改变任何 npm 发布包包含的源文件。

关联 Issue 或背景 / Related Issue or Context

N/A — 这是 PR #164 合并后首次 v0.5.0-rc.1 分阶段发布中发现的发布门禁缺陷,直接修复用于安全恢复同一版本的发布。失败运行:https://github.com/omdsh-dev/dsh-mnemon/actions/runs/33803702613 。16 个插件已经发布;Starter、tag 与 GitHub Prerelease 尚未发布。

涉及区域 / Affected Areas

  • Host 激活、Headless 或 bundle / Host activation, Headless, or bundle
  • 运行时记忆 / Runtime Memory
  • 项目档案 / Project Documents
  • 记忆体或 Provider / Memory Spaces or Providers
  • 子 Agent 或 Agent 工作流 / Subagent or Agent workflow
  • Web UI 或对话交互 / Web UI or conversation interaction
  • 设置、存储或安全 / Settings, storage, or security
  • CLI、RPC、命令或工具 / CLI, RPC, commands, or tools
  • 安装、更新或发布 / Installation, update, or release
  • 测试、构建或文档 / Tests, build, or documentation
  • 其他(请说明)/ Other (explain below)

PR 类型 / PR Type

  • 面向用户的功能或行为变更 / User-facing feature or behavior change
  • Bug 修复 / Bug fix
  • 增强或优化 / Enhancement or optimization
  • 兼容性适配 / Compatibility change
  • 维护或重构 / Maintenance or refactor
  • 测试或构建 / Tests or build

最新代码确认 / Latest Codebase Confirmation

  • 我已基于最新 main 分支开发,或在提交前已 rebase 或合并最新 main。 / I developed from the latest main, or rebased or merged the latest main before submitting.

同步命令 / Sync command:

git fetch origin main && git merge-base --is-ancestor origin/main HEAD

AI 编码披露 / AI Coding Disclosure

  • 完全 AI 编码:全部编程改动由 AI 产出,并由贡献者接受和审查。 / Fully AI-coded: AI produced all programming changes, which the contributor accepted and reviewed.
  • 部分 AI 辅助:AI 帮助编写或修改了部分内容。 / Partially AI-assisted: AI helped write or modify part of the change.
  • 未使用 AI 编码辅助。 / No AI coding assistance was used.

使用的 AI 模型 / AI model used:

OpenAI GPT-5 family (Codex)

使用的编码 Agent 工具 / Coding Agent tool used:

Codex desktop app

仓库规范检查 / Repository Rules

  • 未修改 DSH 官方源码,未让 tsconfig 指向 DSH 源码 checkout,仅使用正式的 @deepseek-ai/* NPM 契约。 / I did not modify DSH source or point tsconfig at a DSH source checkout, and used only published @deepseek-ai/* NPM contracts.
  • Client 与 Host 边界仍以 src/shared/contracts.ts 为准,没有在两侧重复定义 wire DTO。 / The Client and Host boundary still uses src/shared/contracts.ts as the single source for wire DTOs.
  • 持久化格式、RPC 权限、路径或凭据处理的变更包含兼容或拒绝路径、安全分析和相应测试。 / Changes to persistence formats, RPC authority, paths, or credentials include compatibility or rejection paths, security analysis, and tests.
  • 没有提交 token、密钥、私有记忆、未脱敏日志或生成的 lib/ 文件。 / I did not commit tokens, credentials, private memory, unredacted logs, or generated lib/ files.
  • 用户可见文案和长期文档已同步维护中文与英文版本,命令、配置键和路径保持一致。 / User-facing copy and long-lived documentation are synchronized in Chinese and English, with matching commands, configuration keys, and paths.
  • 新增和修改的代码、注释、文档、提交信息不含 emoji。 / New and modified code, comments, documentation, and commits contain no emoji.

兼容性与数据安全 / Compatibility and Data Safety

不改变 DSH、Mnemon、Provider、用户配置、存储格式或现有数据。修复仅让发布后的临时安装目录按照 plan.packages[].manifest.name 定位已安装包并验证精确版本;临时目录仍在 finally 中清理。恢复发布时,已存在的 16 个插件必须逐一与新冻结 tarball 的 Registry integrity 完全一致,否则在 Starter 发布前拒绝继续。

本地验证 / Local Validation

执行的命令 / Commands run:

pnpm exec vitest run tests/release.spec.mjs tests/version-updates.spec.ts
pnpm release:check
pnpm run verify:build
pnpm --workspace-concurrency=1 -r build
git diff --check

结果摘要 / Result summary:

全部通过。发布与 updater 共 32 项测试通过;新增用例在临时目录安装模拟的冻结 Starter 与全部 Registry 插件,并逐个读取实际包清单验证版本,能够在修复前稳定复现 path 收到 undefined 的失败。确定性构建通过 39 个输出文件;全部 16 个 workspace 插件重新构建成功。

用户可见变更证据 / Local Feature Evidence

证据 / Evidence:

N/A — 这是仅影响维护者发布流水线的内部修复,没有用户可见 UI 或运行时行为变化。失败日志和新增回归测试共同提供可复现证据。

@Grivn
Grivn merged commit f62eb53 into main Sep 3, 2026
6 checks passed
@Grivn
Grivn deleted the codex/fix-rc-release-verifier branch September 4, 2026 01:27
@Grivn Grivn mentioned this pull request Sep 4, 2026
27 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant