Skip to content

fix(orca): publish plugins/genie as a tree-only ref instead of a root manifest - #2844

Merged
namastex888 merged 1 commit into
devfrom
feat/orca-plugin-subtree-ref
Aug 30, 2026
Merged

namastex888 merged 1 commit into
devfrom
feat/orca-plugin-subtree-ref

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

Why the repo root can't be an Orca plugin source

Orca 1.4.x installs a plugin from a git URL+ref, or a local folder, whose root holds orca-plugin.json. Its bundled loader enforces three things:

  1. No symlinks anywhere in the tree — the first one fails the whole install with unsafe file path or symlink. This repo has docs -> .docs-vendor/genie.
  2. Max 2000 files / 50 MB — a dev checkout of this repo is roughly 14,000 files.
  3. The manifest must be at the root — genie's lives at plugins/genie/orca-plugin.json, which a git plugin source never looks at.

#2843 added a re-rooted orca-plugin.json at the repo root. That fixes rule 3 only; rules 1 and 2 still make the root tree un-installable, so the root manifest bought nothing and cost a tenth version-stamping target.

plugins/genie on its own satisfies all three: symlink-free, 132 files, 1.3 MB, manifest at its root.

What changed

Removed the root manifest and every stamping hook #2843 added for it

  • deleted orca-plugin.json
  • scripts/version.ts — path + header comment
  • .github/workflows/version.yml — JSON_FILES entry, and "ten version files" back to nine (both the step name and the delta-guard error)
  • scripts/release-guard.sh — the optional version-only child member and its comment
  • the matching assertions in release-guard.test.ts, release-payload-version.test.ts, version-ci-staging.test.ts, version-format.test.ts, release-docs.test.ts

scripts/version.ts, version.yml, and release-guard.sh are now byte-identical to their pre-#2843 state. release-guard.test.ts keeps one #2843 improvement: the not.toContain('orca-plugin.json') substring assertion stays in its stronger split('\n') exact-path form.

Publish the subtree as a tree-only ref — new .github/workflows/orca-plugin-ref.yml:

  • on push to main touching plugins/genie (or the workflow itself), git commit-tree $(git rev-parse HEAD:plugins/genie) produces a parentless commit whose root is plugins/genie, force-pushed to refs/heads/orca-plugin
  • the same from dev to refs/heads/orca-plugin-dev
  • idempotent: it reads the published ref's tree via gh api and exits without pushing when it already equals the branch's subtree hash
  • contents: write is scoped to that one job; top-level is contents: read. The job runs no package script, dependency installer, hook, or any executable from the checkout. actions/checkout is SHA-pinned with persist-credentials: false; credentials are bound with gh auth setup-git right before the push, mirroring version.yml.
  • the ref is tree-only by design (no history, no ancestry with main/dev, never merged back), noted in a comment. Orca pins the commit it fetched, so a republish cannot retroactively change an existing install.

Both refs already exist at the correct trees (origin/main:plugins/genie = 5845229…, origin/dev:plugins/genie = d7dca36…), so the workflow's first real run will be a no-op skip.

Retargeted orca-marketplace.json — single automagik.genie entry, source: { kind: git, url: https://github.com/automagik-dev/genie.git, ref: orca-plugin }. It is now the only Orca file at the repo root: source-only, versionless, in no tarball.

Retargeted scripts/orca-manifest-parity.test.ts — marketplace id == <publisher>.<id> of the payload manifest, description matches, url == <repository>.git, ref == orca-plugin; both JSONs parse; the workflow really is what republishes the ref; plugins/genie has zero symlinks and ≤ 2000 files (enumerated from the git index, i.e. exactly the bytes that get published); the payload main resolves inside the subtree; and no root orca-plugin.json — nor any stamping of one — comes back.

Docs — README "Installing the plugin in Orca", plugins/genie/references/orca-orchestration.md, and the CLAUDE.md gotcha now all state the three loader constraints, the three install routes, and that genie setup --orchestration-mode orca selects authority only and never registers the plugin with Orca.

How to install in Orca

Route What to give Orca
Marketplace source https://github.com/automagik-dev/genie.git, ref main (the index) → resolves the plugin at ref orca-plugin
Plugin git source https://github.com/automagik-dev/genie.git, ref orca-plugin (stable) or orca-plugin-dev (pre-release)
Local folder ~/.genie/plugins/genie

Never main or dev as a plugin source — those roots are the un-installable trees described above.

Validation

bun run typecheck, lint, dead-code, lint:complexity-budget, lint:hook-content, lint:orca-bundle, lint:plugin-skills all clean (lint's 3 warnings are pre-existing complexity warnings in untouched files).

bun test scripts/ → 439 pass / 5 fail. The 5 failures are all in scripts/reconcile-release-assets.test.ts and reproduce identically on a clean origin/dev worktree — sandbox timeouts, unrelated to this change.

Workflow YAML parses; its run block passes bash -n; its actions/checkout pin extracts correctly through scripts/check-action-pins.sh --extract.

🤖 Generated with Claude Code

https://claude.ai/code/session_013gGxGgKskzyzr1HRUB6cV3

… manifest

Orca 1.4.x installs a plugin from a git URL+ref (or a local folder) whose ROOT
holds orca-plugin.json, and its bundled loader rejects any tree containing a
symlink ("unsafe file path or symlink") and caps an install at 2000 files /
50 MB. The genie repository root can never satisfy that: `docs` is a symlink
into the .docs-vendor submodule, and a dev checkout is ~14k files.

#2843 added a repo-root orca-plugin.json to fix the "manifest must be at the
root" rule, but that rule was only one of three — the root tree is still
un-installable. Remove it, and revert every stamping addition it required:
scripts/version.ts, the version.yml JSON_FILES list (back to nine version
files), release-guard.sh's optional child member, and their tests. The
release-guard.test.ts assertion is kept in its stronger exact-path form.

Publish the plugin as a tree-only ref whose root IS plugins/genie instead:
symlink-free, 132 files, 1.3 MB, manifest at its root.
.github/workflows/orca-plugin-ref.yml force-pushes `git commit-tree
HEAD:plugins/genie` — a parentless, history-free commit — to
refs/heads/orca-plugin on push to main and refs/heads/orca-plugin-dev on push
to dev, skipping when the published ref already carries that tree. contents:
write is scoped to that one job, which runs nothing from the checkout.

orca-marketplace.json stays as the only repo-root Orca file and now points at
ref orca-plugin. scripts/orca-manifest-parity.test.ts is retargeted: it checks
the index against the payload manifest's identity and ref, that no root
orca-plugin.json reappears, and that plugins/genie stays symlink-free and
inside Orca's file cap so the published subtree remains installable.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013gGxGgKskzyzr1HRUB6cV3
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-08-30T04:53:28.845615Z ea25480 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Aug 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 2e720eb2-a79e-472b-bb94-d4cda91be794

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ea254804a2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +31 to +38
on:
push:
branches: [main, dev]
paths:
- 'plugins/genie/**'
- '.github/workflows/orca-plugin-ref.yml'
# Manual repair path: republish the current branch tip's subtree.
workflow_dispatch:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Republish the auto-version child

On every normal dev release, this workflow publishes the developer-pushed commit, but .github/workflows/version.yml subsequently rewrites the plugins/genie version metadata and pushes a version-only child using github.token; that workflow itself notes that GITHUB_TOKEN-authored pushes do not trigger workflows. Consequently, orca-plugin-dev remains on the pre-bump tree rather than mirroring the resulting dev tip, so pre-release installations receive stale version metadata until an unrelated qualifying push or manual repair occurs. Explicitly dispatch this publisher after the atomic version push or otherwise add a trigger for the version child.

Useful? React with 👍 / 👎.

Comment on lines +113 to +116
gh auth setup-git
# Force is structural, not a race override: every publish is a fresh
# root commit, so the ref can only ever be replaced, never advanced.
git push --force origin "${COMMIT}:refs/heads/${TARGET_REF}"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject publication from a stale source commit

When a historical successful workflow run is rerun, checkout remains pinned to that run's old push commit, and this unconditional force-push replaces the current orca-plugin or orca-plugin-dev ref with the old subtree. The concurrency group prevents simultaneous publishers but never verifies that SOURCE_SHA is still the source branch tip, so new Orca installations can regress after a rerun; check the current remote main/dev head before publishing and skip stale runs.

Useful? React with 👍 / 👎.

@namastex888
namastex888 merged commit 7b48ee1 into dev Aug 30, 2026
18 checks passed
@namastex888
namastex888 deleted the feat/orca-plugin-subtree-ref branch August 30, 2026 04:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant