Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 9 additions & 2 deletions .github/workflows/busybox-run-probe.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,11 +41,18 @@ jobs:
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5
with:
node-version: 24
cache: 'npm'
# Root deps (runtime polyfills the augmentation preload resolves) + the
# nub-native addon, mirroring ci.yml's Windows test leg — the proven recipe
# that makes `nub run node …` work on a real runner.
- run: npm ci
#
# The root is nub-identity (nub.lock), so a released nub installs it; this
# job builds its own nub only further down, after the deps are needed.
# `hoisted` because the runtime staging and nub-core's build script copy
# real directories out of node_modules and reject a symlinked store.
- uses: ./setup
with:
cache: 'true'
- run: nub install --frozen-lockfile --node-linker hoisted
- name: Build nub-native addon
shell: bash
run: |
Expand Down
44 changes: 33 additions & 11 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -390,11 +390,16 @@ jobs:
# runtime, never from the checkout. Install and stage the locked copies
# before building nub.exe so the release blob contains a self-sufficient
# runtime for the offline --smol gate below.
# A released nub materializes node_modules from nub.lock; the nub under
# test is built in the next step and cannot install its own inputs.
- uses: ./setup
with:
cache: 'true'
- name: Install and stage runtime dependencies for embedded compile
shell: bash
run: |
set -euo pipefail
npm ci
nub install --frozen-lockfile --node-linker hoisted
rm -rf runtime/node_modules
mkdir -p \
runtime/node_modules/@js-temporal \
Expand Down Expand Up @@ -875,10 +880,14 @@ jobs:
- uses: pnpm/action-setup@fc06bc1257f339d1d5d8b3a19a8cae5388b55320 # v5
with:
version: 10
# No `cache: npm` — setup-node's npm cache keys on a lockfile npm can read,
# and the root now carries only nub.lock. Warm deps instead come from the
# `./setup` step further down, which is passed `cache: 'true'`; the action
# defaults that input to "false" and gates its cache steps on it, so
# dropping the input here without adding it there is a cold install.
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5
with:
node-version: ${{ matrix.node }}
cache: 'npm'
# Side-install the off-matrix tier representatives for the version_tiers
# integration test: compat 22.13, unsupported 18.18, detect-module in-band
# 20.11 (flag still required there), and 26.5 (carries the node:ffi/vfs/
Expand Down Expand Up @@ -938,15 +947,28 @@ jobs:
run: |
pnpm --version
npm --version
# Root deps are npm-managed (package-lock.json — same PM wpt-worker's
# root `npm ci` uses; the pnpm domain lives in tools/).
- run: npm ci
# `npm` runs through the Socket Firewall shim, which `exec`s sfw — so sfw's
# status IS this step's status. An sfw crash that exits 0 leaves a
# half-built tree (package dirs present, package.json missing) and a GREEN
# install step; the tree then surfaces six minutes later as unresolvable
# helper imports in five unrelated transpile tests. Assert the install
# actually produced something resolvable, so infra failure fails here.
# Root deps come from nub.lock — the repo root is nub-identity, so nub is
# the only manager that reads it (the pnpm domain still lives in tools/).
# A released nub installs them: this leg builds no nub of its own before
# the tests need the tree. `hoisted` keeps node_modules real directories.
#
# THIS INSTALL NO LONGER PASSES THROUGH THE SOCKET FIREWALL SHIM. sfw is
# wired by shimming `npm`/`pnpm` by NAME on PATH, and `nub` carries no such
# shim, so the interception that covered the old `npm ci` does not cover
# this step. What still holds on EVERY leg: nub.lock pins each tarball by
# integrity hash and `--frozen-lockfile` refuses to re-resolve. Lifecycle
# confinement does NOT hold everywhere — the build jail is Linux (landlock
# + seccomp) and macOS only (aube-scripts/src/lib.rs has no Windows arm),
# so on the windows-latest cell the mitigation is the pinned lockfile
# alone. The shims stay for the pnpm/npm surfaces the tests drive.
- uses: ./setup
with:
cache: 'true'
- run: nub install --frozen-lockfile --node-linker hoisted
# An installer that exits 0 on a half-built tree (package dirs present,
# package.json missing) surfaces six minutes later as unresolvable helper
# imports in five unrelated transpile tests. Assert the install actually
# produced something resolvable, so infra failure fails HERE.
- name: assert root deps actually installed
run: node -e "require.resolve('@oxc-project/runtime/helpers/usingCtx')"
# The data-format loader tests need the nub-native addon (the npm yaml/toml/
Expand Down
20 changes: 13 additions & 7 deletions .github/workflows/compile-native.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ on:
- 'vendor/libsui/**'
- 'npm/**'
- 'package.json'
- 'package-lock.json'
- 'nub.lock'
- 'tests/compile-native-islands/**'
- 'tests/compile-augmentation/**'
- 'tests/compile-corpus/**'
Expand All @@ -31,7 +31,7 @@ on:
- 'vendor/libsui/**'
- 'npm/**'
- 'package.json'
- 'package-lock.json'
- 'nub.lock'
- 'tests/compile-native-islands/**'
- 'tests/compile-augmentation/**'
- 'tests/compile-corpus/**'
Expand Down Expand Up @@ -80,12 +80,16 @@ jobs:
# and this is not pinned to a prebuild matrix. The only floor is sharp's
# own `engines: >=20.9.0`.
node-version: '24'
cache: npm
# Only bootstrap the compiler's locked pure-JS dependencies. The fixture's
# application install below MUST use the just-built Nub candidate.
# application install below MUST use the just-built Nub candidate — this
# released nub exists only to materialize node_modules from nub.lock.
# `hoisted` because the staging below `cp -R`s real directories out of it.
- uses: ./setup
with:
cache: 'true'
- name: Install compiler bootstrap dependencies
shell: bash
run: npm ci
run: nub install --frozen-lockfile --node-linker hoisted
- name: Build fresh native candidate and matching launcher
shell: bash
run: |
Expand Down Expand Up @@ -228,10 +232,12 @@ jobs:
# container below derives its own `--target`. Same major as
# `native-host` so the matrix reads as one Node line.
node-version: '24'
cache: npm
- uses: ./setup
with:
cache: 'true'
- name: Install compiler bootstrap dependencies
shell: bash
run: npm ci
run: nub install --frozen-lockfile --node-linker hoisted
- name: Install pinned cross tool
shell: bash
run: cargo install cross --version 0.2.5 --locked
Expand Down
15 changes: 9 additions & 6 deletions .github/workflows/lat-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,12 +35,15 @@ jobs:
node-version: 26

# The checker is fetched by `npx` at an exact pinned version rather than added
# to the root package.json. It brings ~185 transitive packages, and every ci.yml
# test leg runs the root `npm ci` through the Socket Firewall shim, where an sfw
# crash that exits 0 leaves a half-built tree and a green install step (see the
# "assert root deps actually installed" guard in ci.yml). Adding that much to the
# root install tripped exactly that guard across the whole matrix. The version
# lives once, in the `lat:check` script.
# to the root package.json. It brings ~185 transitive packages, and an installer
# that exits 0 on a half-built tree leaves a green install step (see the "assert
# root deps actually installed" guard in ci.yml). Adding that much to the root
# install tripped exactly that guard across the whole matrix. The version lives
# once, in the `lat:check` script.
#
# The Socket Firewall shim is no longer part of that story: the root is
# nub-identity, and every leg now installs it with `nub install`, which
# carries no sfw shim.
- name: wiki/ carries no internal-only material
run: node scripts/wiki-public-lint.mjs

Expand Down
31 changes: 26 additions & 5 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -512,8 +512,16 @@ jobs:
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 # zizmor: ignore[cache-poisoning] test gate only; node_modules here only feed cargo test
with:
node-version: "24"
cache: "npm"
- run: npm ci
# The root is nub-identity (nub.lock), so nub installs its own deps. The
# release workflow deliberately uses the nub it BUILDS, never a published
# one: bootstrapping a release from the last release means a broken
# release wedges the very workflow that would publish the fix. The debug
# build is nearly free here because `cargo test` below compiles the same
# crates in the same profile.
- name: Install JS dependencies with the nub built here
run: |
cargo build -p nub-cli
./target/debug/nub install --frozen-lockfile --node-linker hoisted
# The data-format loader tests (data_format_loaders, and the env-* tests whose
# fixture imports a .json5/.yaml file) need the nub-native addon — the npm
# parser fallback (yaml/@iarna/toml/json5) isn't a dev dependency, so without
Expand Down Expand Up @@ -647,10 +655,23 @@ jobs:
- uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5 # zizmor: ignore[cache-poisoning] tag runs restore only caches saved by main/tag runs (PR caches are branch-isolated), so seeding requires push access
with:
node-version: "24"
cache: "npm"

- name: Install JS dependencies
run: npm ci
# These deps are staged into the embedded runtime, so they must exist
# before the release binary is built — but the publish path must never
# bootstrap from a PUBLISHED nub, or a broken release wedges the workflow
# that would publish its fix. So build a HOST nub first and install with
# it. Host, not `matrix.target`: this binary is a build tool that runs on
# the runner, never an artifact, so a cross leg still builds it natively.
# `hoisted` keeps node_modules real directories for the staging below.
#
# No store cache here, deliberately: caching rides on the `./setup` action,
# and using it would put a PUBLISHED nub on this job — the one thing the
# publish path must not depend on. The root is six direct dependencies, so
# a cold install costs seconds against a build measured in minutes.
- name: Install JS dependencies with a host nub built here
run: |
cargo build -p nub-cli
./target/debug/nub install --frozen-lockfile --node-linker hoisted

# Canary builds self-report the canary version: `--version` is asserted by
# the pre-publish gate and NUB_VERSION keys the transpile cache, so every
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/wpt-worker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -67,8 +67,11 @@ jobs:
(cd crates/nub-native && cargo build)
mkdir -p runtime/addons
cp target/debug/libnub_native.so runtime/addons/nub-native.node
# The nub built directly above installs the root deps — this leg never
# needs a published nub. `--ignore-scripts` is preserved; `hoisted` keeps
# node_modules a tree of real directories for the bundle staging below.
- name: Install runtime npm deps
run: npm ci --ignore-scripts
run: ./target/debug/nub install --frozen-lockfile --ignore-scripts --node-linker hoisted
- name: Stage the reusable nub bundle
shell: bash
run: |
Expand Down
8 changes: 6 additions & 2 deletions .worktreeinclude
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ symlink .repos

# Internal design corpus (plans, command/runtime specs, research). Gitignored so
# absent in a fresh worktree — symlinked so an impl agent can read the canonical
# spec a .fray thread points to (e.g. wiki/commands/init.md).
# spec a frizz thread points to (e.g. wiki/commands/init.md).
symlink wiki

# fray orchestration control surface. Symlinked so a worktree-isolated sub-agent
Expand All @@ -32,7 +32,11 @@ symlink wiki
# (the sandbox check is path-prefix based and doesn't resolve symlinks).
# NOTE: this covers SCRIPTED worktrees (new-worktree.ts). HARNESS-created
# isolation:worktree worktrees do NOT run new-worktree.ts — those rely on the
# dispatch-prompt step-0 `ln -s <abs-shared-root>/.fray .fray`.
# dispatch-prompt step-0 `ln -s <abs-shared-root>/.frizz .frizz`.
# Both names: the tool was renamed fray -> frizz, and only the old name was
# listed, so a scripted worktree silently got NO orchestration surface
# ("source missing, skipping '.fray'").
symlink .frizz
symlink .fray

# The prebuilt N-API addon. `--all-features` turns on `embed-runtime`, whose
Expand Down
29 changes: 0 additions & 29 deletions bun.lock

This file was deleted.

Loading
Loading