Skip to content

fix(pack): include host-migrations files in npm tarball - #1622

Merged
namastex888 merged 1 commit into
devfrom
fix/migrations-tarball-files
May 3, 2026
Merged

namastex888 merged 1 commit into
devfrom
fix/migrations-tarball-files

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

Summary

Two-line fix to package.json files array. PR #1619 added the host-migrations framework but the files whitelist was not updated, so the published tarball excluded both the postinstall hook script and the entire src/migrations/ source directory.

Symptom on the just-released 4.260503.5

After genie update --next on a host:

$ genie --no-tui migrate --status
No migrations discovered.

Verified via tarball inspection:

$ curl -sL https://registry.npmjs.org/@automagik/genie/-/genie-4.260503.5.tgz | tar -tzf - | grep migration
package/src/db/migrations/...   # only DB migrations
# scripts/postinstall-migrations.js MISSING
# src/migrations/{runner,discover,store,steps/*}.ts MISSING

So the migrate command in the bundled dist/genie.js runs, but discoverMigrations() scans a src/migrations/steps/ path that doesn't exist in the installed package → empty list → silent "no migrations." The whole framework is non-functional in published artifacts. Postinstall chain ... && node scripts/postinstall-migrations.js also silently fails (bun's default trust policy blocks it on global installs anyway).

Wish acceptance bullet broken

.genie/wishes/genie-host-migrations/WISH.md:

"Auto-runs on bun add -g @automagik/genie@latest via postinstall hook so users get fixes transparently."

This was impossible until both files ship in the tarball.

Diff

   "scripts/postinstall-tmux.js",
   "scripts/postinstall-hook-binary.js",
+  "scripts/postinstall-migrations.js",
   "scripts/sec-scan.cjs",
   ...
   "src/db/migrations/",
+  "src/migrations/",
   "templates/",

Verification

$ npm pack --dry-run | grep -E "(postinstall-migrations|src/migrations)"
npm notice 2.2kB scripts/postinstall-migrations.js
npm notice 1.8kB src/migrations/discover.ts
npm notice 3.8kB src/migrations/index.ts
npm notice 2.4kB src/migrations/runner.ts
npm notice 3.4kB src/migrations/steps/001-pm2-env-databaseurl-bake.ts
npm notice 3.8kB src/migrations/steps/002-kill-embedded-pgserve-legacy.ts
npm notice 2.6kB src/migrations/store.ts
npm notice 2.8kB src/migrations/README.md
npm notice 3.7kB src/migrations/__tests__/orchestrator.test.ts

Test plan

  • CI green
  • After merge + auto-version bump + npm publish: bun add -g @automagik/genie@next on a fresh host → tarball includes both new entries
  • genie migrate --status lists the 2 shipped steps (or "no pending" if already applied)
  • genie update --next → post-update maintenance section shows a [ok]/[fix]/[!!] migrations line (if/when the post-update flow is taught to surface migrations status — separate follow-up)

Out of scope

  • Migration step files include src/migrations/__tests__/orchestrator.test.ts (3.7kB) — minor waste, not worth a glob exclusion
  • Adding a migrations line to the post-update maintenance summary — separate cosmetic follow-up

🤖 Generated with Claude Code

PR #1619 added the host-migrations framework but `package.json`
`files` array did not include `scripts/postinstall-migrations.js`
nor `src/migrations/`. Result on published 4.260503.5:

  $ tar -tzf @automagik-genie-4.260503.5.tgz | grep migration
  package/src/db/migrations/...   # only DB migrations shipped
  # scripts/postinstall-migrations.js MISSING
  # src/migrations/{runner,discover,store,steps/*}.ts MISSING

Symptom on `bun add -g @automagik/genie@next && genie update --next`:
- postinstall chain has `node scripts/postinstall-migrations.js` but
  the file is absent (silent failure under bun's default trust policy).
- `genie migrate --status` returns "No migrations discovered."
  because `discoverMigrations()` scans a non-existent directory.

Wish acceptance bullet from `.genie/wishes/genie-host-migrations`:
  "Auto-runs on `bun add -g @automagik/genie@latest` via postinstall
   hook so users get fixes transparently."
This made the bullet impossible. Two-line fix to make it actually
work in the next release.

Verified via `npm pack --dry-run`:
  npm notice 2.2kB scripts/postinstall-migrations.js
  npm notice 1.8kB src/migrations/discover.ts
  npm notice 3.8kB src/migrations/index.ts
  npm notice 2.4kB src/migrations/runner.ts
  npm notice 3.4kB src/migrations/steps/001-pm2-env-databaseurl-bake.ts
  npm notice 3.8kB src/migrations/steps/002-kill-embedded-pgserve-legacy.ts
  npm notice 2.6kB src/migrations/store.ts
  npm notice 2.8kB src/migrations/README.md

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented May 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 3b140f56-9d06-45de-be2f-dd13f55bb459

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/migrations-tarball-files

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@namastex888
namastex888 merged commit 9ae0e7f into dev May 3, 2026
16 checks passed

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates package.json to include the postinstall-migrations.js script and the src/migrations/ directory in the published package. Feedback highlights a potential runtime failure where the post-install script might incorrectly use Node.js to execute a Bun-targeted bundle, and a path resolution issue in the migrations logic that could lead to incorrect version reporting in production.

Comment thread package.json
"plugins/genie/",
"scripts/postinstall-tmux.js",
"scripts/postinstall-hook-binary.js",
"scripts/postinstall-migrations.js",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The postinstall script scripts/postinstall-migrations.js (added here to the npm package) uses process.execPath to execute the genie.js bundle. Since the postinstall script in package.json is explicitly invoked with node, process.execPath will point to the Node.js binary. However, the bundle is built with --target bun and likely depends on Bun-specific APIs (as indicated by the bun engine requirement and externalized bun dependency). Running this bundle with Node.js will likely fail, preventing migrations from running during installation. Consider detecting and using bun to execute the bundle if it is a Bun-only artifact.

Comment thread package.json
"scripts/sec-fix.cjs",
"scripts/tmux/",
"src/db/migrations/",
"src/migrations/",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

While including src/migrations/ is necessary for dynamic discovery, note that src/migrations/index.ts calculates the package.json path as ../../package.json. This works in the source tree but is incorrect for the bundled dist/genie.js (where __dirname is dist/). In the bundled state, the path should be ../package.json. This will cause getGenieVersion() to return "unknown" in production migration logs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant