Skip to content

fix(build): preserve full dashboard in release packages - #13656

Open
jbovard2016 wants to merge 7 commits into
diegosouzapw:release/v3.8.52from
jbovard2016:fix/jon-1228-full-release
Open

jbovard2016 wants to merge 7 commits into
diegosouzapw:release/v3.8.52from
jbovard2016:fix/jon-1228-full-release

Conversation

@jbovard2016

Copy link
Copy Markdown
Contributor

Summary

  • separate browser-safe provider alias and CodeBuddy CN metadata from server-only modules
  • bind every standalone build to an explicit BUILD_PROFILE
  • reject stale or cross-profile standalone reuse during packaging
  • require full-profile dashboard routes, client manifests, and static assets in release packages
  • repair OpenCode plugin dependency installation under production builds

Verification

  • focused JON-1228/JON-562/JON-563 suite: 79 passed
  • build/package focused suites: 504 passed in independent review
  • npm run typecheck:core: passed
  • npm run typecheck:noimplicit:core: passed
  • changed-file ESLint and Prettier: passed
  • npm run build:release: passed; committed BUILD_SHA=fa57b036, BUILD_PROFILE=full
  • OMNIROUTE_RELEASE_REF=HEAD npm run check:pack-artifact: passed
  • npm run check:pack-boot: passed install, auth, persistence, and restart
  • npm run check:install-upgrade -- --from 3.8.50: passed; schema 130 → 133
  • isolated loopback canary: UAT-01 through UAT-09 passed; canary stopped after testing

Known inherited base failures

⚠️ base-red inherited: #12732

Full lint remains red only on four unchanged errors reproduced on origin/release/v3.8.51. The full unit run also hits the inherited Adobe Firefly stall recorded in #12732. Changed files lint clean.

Artifact identity

  • source commit: fa57b03692f1757e3df63efe7618d09b97d95280
  • package: omniroute-3.8.51.tgz
  • SHA-256: afbc2296ca8056ad07c4372c43f0dcc5196102c098f96ca1ea67da9441c81d8c
  • packed size: 113,562,929 bytes
  • dist/BUILD_SHA: fa57b036
  • dist/BUILD_PROFILE: full

Refresh stale critical pressure at the structural request gate so recovered processes admit work again. Bound the shared refresh wait and preserve fail-open behavior after the stale window.
Completed request previews used V8 sliced strings that kept multi-megabyte request backing stores alive. Detach and byte-bound cached details, and add a credential-free profiler with cleanup and physical-retention assertions.
Define the full-dashboard release boundary, implementation sequence, UAT, rollback, traceability, and risk decisions after the API-only candidate produced a blank dashboard.
Separate browser-safe provider metadata from server-only modules and bind package validation to an explicit build profile plus real dashboard artifacts. This prevents a healthy API-only package from being accepted as the user-facing release.
@jbovard2016

Copy link
Copy Markdown
Contributor Author

Ready for maintainer merge. Semgrep passed; independent code and package reviews accepted; commit-bound full package passed build, pack-artifact, pack-boot, upgrade, and isolated UAT-01..09. The contributor account cannot merge this repository. ⚠️ Base-red inheritance remains documented in #12732.

Cap active and queued artifact payloads by estimated bytes before worker cloning and serialization. Fail open by omitting detail while preserving summary writes when the queue is saturated or estimation fails.
Distinguish byte overflow from estimator traversal exhaustion, trim oversized pipeline detail before recursive privacy processing, and preserve conservative worker queue accounting for high-node artifacts.
@diegosouzapw

Copy link
Copy Markdown
Owner

Really thorough work on the client-bundle-safety piece — the codebuddyCn.ts extraction and the
generalized node:* guard test are excellent, and I verified they fully close the same bundling
leak that a couple of other open PRs (#13604 et al.) are independently fixing for the cursor-CLI
pin, via a different (complementary, not conflicting) edge cut. That part alone would be
merge-ready.
The PR as a whole, though, bundles that fix together with a 9-document platform-recovery
proposal, resource-pressure/usage/memory-profiling changes, and pack-artifact policy work — five
largely unrelated concerns in one 3000+ line diff, which is really hard to review safely as a
unit. Would you be open to splitting out just the client-bundle-safety commits into their own
PR first? That part can land quickly on its own; the rest deserves its own focused review (and
the proposal docs probably belong in a planning/RFC space rather than the docs/ tree).

@diegosouzapw diegosouzapw changed the title fix(build): preserve full dashboard in release packages [defer] fix(build): preserve full dashboard in release packages Sep 15, 2026
@diegosouzapw
diegosouzapw changed the base branch from release/v3.8.51 to release/v3.8.52 September 29, 2026 11:25
@diegosouzapw

Copy link
Copy Markdown
Owner

Re-homed to release/v3.8.52: v3.8.51 entered its release freeze, so the branch now belongs to the release captain and development continues on the next cycle. Nothing is wrong with this PR — it just needed a live base. No action needed from you; CI will re-run against the new base.

@diegosouzapw diegosouzapw changed the title [defer] fix(build): preserve full dashboard in release packages fix(build): preserve full dashboard in release packages Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants