fix(build): require dist/tls-options.mjs in pack artifact guard (#5452) - #5504
diegosouzapw wants to merge 1 commit into
Conversation
dist/server-ws.mjs and dist/open-sse/mcp-server/server.js import ./tls-options.mjs (opt-in HTTPS/TLS resolver, #5242), but the sidecar was absent from PACK_ARTIFACT_REQUIRED_PATHS. When the 3.8.41 tarball was assembled without it, check:pack-artifact stayed green and a fresh `omniroute serve` crashed with ERR_MODULE_NOT_FOUND. Mark it required so the publish gate fails fast if it is ever dropped again. Regression guard: tests/unit/pack-artifact-policy.test.ts.
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Closing as redundant — superseded by #5503, which already merged the complete fix into #5503's fix is more complete than this PR: it adds both the staging-allowlist entry for No further action needed here — |
Closes #5452
Problem
A fresh
npm i -g omniroute@3.8.41crashes onomniroute servewithERR_MODULE_NOT_FOUND: dist/tls-options.mjs imported from dist/server-ws.mjs(confirmed on macOS by @DKotsyuba and Windows by @containmethod). Same class as #5227.Root cause
dist/server-ws.mjs(anddist/open-sse/mcp-server/server.js) import./tls-options.mjs— the opt-in HTTPS/TLS resolver added in #5242. The assembler (assembleStandalone→syncExtraModulesToDir) copies it intodist/, but it was missing fromPACK_ARTIFACT_REQUIRED_PATHSinscripts/build/pack-artifact-policy.ts. Every other server-ws sidecar (server-ws.mjs,responses-ws-proxy.mjs,peer-stamp.mjs,webdav-handler.mjs,http-method-guard.cjs) is required —tls-options.mjswas the gap. So when the 3.8.41 artifact was assembled without it (the release ran through a 34-commit parallel-session race),check:pack-artifactshipped green and users crashed at boot.Fix
Add
"dist/tls-options.mjs"toPACK_ARTIFACT_REQUIRED_PATHS, grouped with its sibling server-ws sidecars.check:pack-artifact(run inprepublishOnly+ CI) now asserts the file is packed and fails fast if it is ever dropped again.Validation (Hard Rule #18 — TDD)
tests/unit/pack-artifact-policy.test.ts:PACK_ARTIFACT_REQUIRED_PATHSincludesdist/tls-options.mjs) — failed before, passes after;findMissingArtifactPathsflags exactlydist/tls-options.mjs) — proves the guard would have blocked the publish;findMissingArtifactPathsexpectation updated.CI's
check:pack-artifactprovides the integration proof that the current build actually emitsdist/tls-options.mjs.Scope
Build/pack policy + test only. No runtime code change.
Follow-up (separate issue, not this PR): the reporter's suggested generalized guard — assert every relative import inside shipped
dist/**resolves to a packed file — would catch this whole class (#5227 + #5452 + future).