mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-02 02:07:25 +08:00
> Follow-up to #11006 (merged): rebased onto master and ready for review. ## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The release subsystem now publishes canary (every master push), nightly (scheduled, smoke-gated, added in #11006), and stable (manual) > - There is still no human-approved release-candidate lane between nightly and stable, and nothing enforces that a stable actually soaked anywhere before shipping > - Betas need a real approval gate, and stables need a soak policy that is data, not prose > - This pull request adds the beta channel: a manual promotion of a chosen nightly behind the `npm-beta` environment gate, re-smoked after publish, plus a stable preflight that enforces a 3-day beta soak with a written-justification bypass > - The benefit is a complete canary → nightly → beta → stable train where every stable shipped as a beta first, and emergencies leave a written trace ## Linked Issues or Issue Description **Subsystem affected** Release automation: `scripts/release.sh`, `scripts/release-lib.sh`, `.github/workflows/release.yml`, `.github/workflows/docker.yml`, `.github/workflows/release-smoke.yml`. **Problem or motivation** After #11006 the project has canary and nightly prerelease lanes, but no release-candidate lane. Stable promotion has no enforced soak: any ref can ship as stable directly. There is no approval boundary for a broader-audience prerelease, and no structured way to record why an emergency release skipped validation. **Proposed solution** Add a `beta` channel: a manual dispatch that promotes a chosen nightly's source commit, publishes behind the `npm-beta` GitHub environment (required reviewers are the gate), re-smokes the published beta, and tags `beta/vX`. Enforce in the stable path that the source commit shipped as a beta at least 3 days earlier (measured from the beta's npm publish time), with a `skip_soak_justification` input as the recorded emergency bypass. **Alternatives considered** Codifying the soak policy in docs only. Rejected: an unenforced policy decays; the preflight makes the policy executable while the justification input keeps the emergency path usable and auditable. ## What Changed - `scripts/release.sh` + `scripts/release-lib.sh`: `beta` channel — requires HEAD to carry a `nightly/v*` tag, publishes the package set as `YYYY.MDD.P-beta.N` under dist-tag `beta`, tags `beta/vYYYY.MDD.P-beta.N` - `.github/workflows/release.yml`: - `channel: beta` dispatch path: `select_beta` resolves the newest (or an explicit `source_version`) nightly and fails loudly on selection problems; `publish_beta` runs behind the `npm-beta` environment, pushes the tag, and dispatches `docker.yml`; `smoke_beta` re-runs the release smoke suite against the exact published beta version - stable path: new `preflight_stable` job enforces the 3-day beta soak from the beta's npm publish time; `skip_soak_justification` bypasses with the reason echoed into the job summary; dry runs report without blocking - `.github/workflows/docker.yml`: `beta/v*` tags publish `:beta` on both images, with exact version stamping - `.github/workflows/release-smoke.yml`: `beta` added to the dispatch choice list - Docs: `CHANNELS.md` beta entries; `RELEASING.md` beta lane, soak gate, and failure playbook; `RELEASE-AUTOMATION-SETUP.md` `npm-beta` environment setup, including the warning to create the environment before the first beta dispatch (GitHub auto-creates unprotected environments on first reference) - Tests: beta version-counting coverage in `scripts/release-registry-versions.test.mjs`; beta identity and nightly-tag guard coverage in `scripts/__tests__/release-dry-run-notes.test.mjs` ## Verification - `node --test` on the two touched suites: 17 pass, including the 3 new beta tests - `bash -n` on both shell scripts and YAML parse of all three workflows - After merge, in order: create the `npm-beta` environment, dispatch `channel: beta` with `dry_run: true` to preview, then a real promotion of a published nightly through the approval gate, then a stable dry-run against a young beta to see the soak gate report ## Risks - If the `npm-beta` environment does not exist when the first beta dispatch runs, GitHub creates it with no protection rules and the beta publishes without approval. Mitigated by documentation and by creating the environment before merge (operator step) - Until the first beta exists, every stable dispatch requires `skip_soak_justification`. This is deliberate — the first beta ships immediately after this merges — but it is a behavior change to the stable dispatch - The soak clock reads the beta's npm publish time from the registry; a registry outage makes the preflight fall back to requiring justification (fail-closed) ## Model Used Claude Fable 5 (`claude-fable-5`, Anthropic) in Claude Code, with extended thinking and full tool use (repository exploration, local test execution, live registry and git verification). All code, tests, and docs in this PR were model-authored under human direction. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green (pending — will confirm before merge) - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups (pending — will confirm before merge) - [x] I will address all Greptile and reviewer comments before requesting merge
476 lines
14 KiB
JavaScript
476 lines
14 KiB
JavaScript
#!/usr/bin/env node
|
|
|
|
import { pathToFileURL } from "node:url";
|
|
|
|
const CANARY_VERSION_RE = /-canary\.\d+$/;
|
|
const PRERELEASE_VERSION_RE = /-(?:canary|nightly|beta)\.\d+$/;
|
|
// Channels that publish prerelease versions and must never move `latest`.
|
|
const PRERELEASE_CHANNELS = new Set(["canary", "nightly", "beta"]);
|
|
const EXIT_RETRIABLE_FAILURE = 1;
|
|
const EXIT_NON_RETRIABLE_FAILURE = 2;
|
|
|
|
export function isCanaryVersion(version) {
|
|
return CANARY_VERSION_RE.test(version);
|
|
}
|
|
|
|
export function isPrereleaseVersion(version) {
|
|
return PRERELEASE_VERSION_RE.test(version);
|
|
}
|
|
|
|
function createExitError(message, exitCode = EXIT_RETRIABLE_FAILURE) {
|
|
return Object.assign(new Error(message), { exitCode });
|
|
}
|
|
|
|
function createProblem(message, { retriable = true } = {}) {
|
|
return { message, retriable };
|
|
}
|
|
|
|
function usage() {
|
|
process.stderr.write(
|
|
[
|
|
"Usage:",
|
|
" node scripts/verify-release-registry-state.mjs --channel <canary|nightly|beta|stable> --dist-tag <tag> --target-version <version> --package <name> [--package <name> ...] [--allow-canary-latest]",
|
|
"",
|
|
].join("\n"),
|
|
);
|
|
}
|
|
|
|
function parseArgs(argv) {
|
|
const options = {
|
|
channel: "",
|
|
distTag: "",
|
|
targetVersion: "",
|
|
allowCanaryLatest: false,
|
|
packages: [],
|
|
};
|
|
|
|
for (let index = 0; index < argv.length; index += 1) {
|
|
const arg = argv[index];
|
|
|
|
switch (arg) {
|
|
case "--channel":
|
|
options.channel = argv[index + 1] ?? "";
|
|
index += 1;
|
|
break;
|
|
case "--dist-tag":
|
|
options.distTag = argv[index + 1] ?? "";
|
|
index += 1;
|
|
break;
|
|
case "--target-version":
|
|
options.targetVersion = argv[index + 1] ?? "";
|
|
index += 1;
|
|
break;
|
|
case "--package":
|
|
options.packages.push(argv[index + 1] ?? "");
|
|
index += 1;
|
|
break;
|
|
case "--allow-canary-latest":
|
|
options.allowCanaryLatest = true;
|
|
break;
|
|
case "-h":
|
|
case "--help":
|
|
usage();
|
|
process.exit(0);
|
|
default:
|
|
throw createExitError(`unexpected argument: ${arg}`, EXIT_NON_RETRIABLE_FAILURE);
|
|
}
|
|
}
|
|
|
|
if (!PRERELEASE_CHANNELS.has(options.channel) && options.channel !== "stable") {
|
|
throw createExitError("--channel must be canary, nightly, beta, or stable", EXIT_NON_RETRIABLE_FAILURE);
|
|
}
|
|
|
|
if (!options.distTag) {
|
|
throw createExitError("--dist-tag is required", EXIT_NON_RETRIABLE_FAILURE);
|
|
}
|
|
|
|
if (!options.targetVersion) {
|
|
throw createExitError("--target-version is required", EXIT_NON_RETRIABLE_FAILURE);
|
|
}
|
|
|
|
if (options.packages.length === 0 || options.packages.some((name) => !name)) {
|
|
throw createExitError("at least one non-empty --package value is required", EXIT_NON_RETRIABLE_FAILURE);
|
|
}
|
|
|
|
if (options.allowCanaryLatest && options.channel !== "canary") {
|
|
throw createExitError("--allow-canary-latest only applies to canary releases", EXIT_NON_RETRIABLE_FAILURE);
|
|
}
|
|
|
|
return options;
|
|
}
|
|
|
|
function createRegistryUrl(packageName, version = "") {
|
|
const registry = process.env.npm_config_registry ?? process.env.NPM_CONFIG_REGISTRY ?? "https://registry.npmjs.org/";
|
|
const baseUrl = registry.endsWith("/") ? registry : `${registry}/`;
|
|
const encodedPackage = encodeURIComponent(packageName);
|
|
|
|
if (!version) {
|
|
return new URL(encodedPackage, baseUrl);
|
|
}
|
|
|
|
return new URL(`${encodedPackage}/${encodeURIComponent(version)}`, baseUrl);
|
|
}
|
|
|
|
export async function fetchRegistryJson(url, { allowMissing = false, timeoutMs = 30_000 } = {}) {
|
|
const controller = new AbortController();
|
|
const timeout = setTimeout(() => controller.abort(), timeoutMs);
|
|
let response;
|
|
|
|
try {
|
|
response = await fetch(url, {
|
|
signal: controller.signal,
|
|
headers: {
|
|
accept: "application/vnd.npm.install-v1+json, application/json;q=0.9",
|
|
},
|
|
});
|
|
} catch (error) {
|
|
if (error instanceof Error && error.name === "AbortError") {
|
|
throw new Error(`npm registry request timed out for ${url} after ${timeoutMs}ms`);
|
|
}
|
|
throw error;
|
|
} finally {
|
|
clearTimeout(timeout);
|
|
}
|
|
|
|
if (response.status === 404 && allowMissing) {
|
|
return null;
|
|
}
|
|
|
|
if (!response.ok) {
|
|
throw new Error(`npm registry request failed for ${url}: ${response.status} ${response.statusText}`);
|
|
}
|
|
|
|
return response.json();
|
|
}
|
|
|
|
async function fetchPackageDocument(packageName, { allowMissing = false } = {}) {
|
|
return fetchRegistryJson(createRegistryUrl(packageName), { allowMissing });
|
|
}
|
|
|
|
async function fetchPackageManifest(packageName, version, { allowMissing = false } = {}) {
|
|
return fetchRegistryJson(createRegistryUrl(packageName, version), { allowMissing });
|
|
}
|
|
|
|
export function createManifestLookupKey(packageName, version) {
|
|
return `${packageName}@${version}`;
|
|
}
|
|
|
|
function isRangeVersionSpecifier(version) {
|
|
return /[\^~*xX><| ]/.test(version);
|
|
}
|
|
|
|
function resolvePublishedManifest(packageName, version, packageDoc, packageManifestsByKey = new Map()) {
|
|
const directManifest = packageManifestsByKey.get(createManifestLookupKey(packageName, version));
|
|
if (directManifest) {
|
|
return directManifest;
|
|
}
|
|
|
|
if (directManifest === null) {
|
|
return null;
|
|
}
|
|
|
|
return packageDoc?.versions?.[version] ?? null;
|
|
}
|
|
|
|
function collectInternalDependencyProblemEntries(
|
|
manifest,
|
|
packageDocsByName,
|
|
packageManifestsByKey = new Map(),
|
|
) {
|
|
const problems = [];
|
|
const sections = [
|
|
["dependencies", manifest.dependencies ?? {}],
|
|
["optionalDependencies", manifest.optionalDependencies ?? {}],
|
|
["peerDependencies", manifest.peerDependencies ?? {}],
|
|
];
|
|
|
|
for (const [sectionName, deps] of sections) {
|
|
for (const [dependencyName, dependencyVersion] of Object.entries(deps)) {
|
|
if (!dependencyName.startsWith("@paperclipai/")) {
|
|
continue;
|
|
}
|
|
|
|
if (typeof dependencyVersion !== "string" || !dependencyVersion) {
|
|
problems.push(
|
|
createProblem(
|
|
`${sectionName} declares ${dependencyName} with a non-string version: ${JSON.stringify(dependencyVersion)}`,
|
|
),
|
|
);
|
|
continue;
|
|
}
|
|
|
|
// Peer dependency ranges express compatibility, not a manifest that can be fetched directly.
|
|
if (sectionName === "peerDependencies" && isRangeVersionSpecifier(dependencyVersion)) {
|
|
continue;
|
|
}
|
|
|
|
const dependencyManifest = resolvePublishedManifest(
|
|
dependencyName,
|
|
dependencyVersion,
|
|
packageDocsByName.get(dependencyName),
|
|
packageManifestsByKey,
|
|
);
|
|
const dependencyLookupKey = createManifestLookupKey(dependencyName, dependencyVersion);
|
|
|
|
if (!dependencyManifest) {
|
|
const dependencyDoc = packageDocsByName.get(dependencyName);
|
|
if (!dependencyDoc && !packageManifestsByKey.has(dependencyLookupKey)) {
|
|
problems.push(
|
|
createProblem(
|
|
`${sectionName} requires ${dependencyName}@${dependencyVersion}, but npm publication metadata was not fetched for that dependency`,
|
|
),
|
|
);
|
|
continue;
|
|
}
|
|
|
|
problems.push(
|
|
createProblem(
|
|
`${sectionName} requires ${dependencyName}@${dependencyVersion}, but npm does not expose that version`,
|
|
),
|
|
);
|
|
}
|
|
}
|
|
}
|
|
|
|
return problems;
|
|
}
|
|
|
|
export function collectInternalDependencyProblems(
|
|
manifest,
|
|
packageDocsByName,
|
|
packageManifestsByKey = new Map(),
|
|
) {
|
|
return collectInternalDependencyProblemEntries(
|
|
manifest,
|
|
packageDocsByName,
|
|
packageManifestsByKey,
|
|
).map((problem) => problem.message);
|
|
}
|
|
|
|
function requireManifest(packageName, version, packageDoc, packageManifestsByKey, problems) {
|
|
const manifest = resolvePublishedManifest(packageName, version, packageDoc, packageManifestsByKey);
|
|
if (!manifest) {
|
|
if (problems) {
|
|
problems.push(createProblem(`${packageName}: npm registry is missing manifest data for ${version}`));
|
|
}
|
|
return null;
|
|
}
|
|
return manifest;
|
|
}
|
|
|
|
export function verifyPackageRegistryProblems({
|
|
packageName,
|
|
packageDoc,
|
|
packageDocsByName,
|
|
packageManifestsByKey = new Map(),
|
|
channel,
|
|
distTag,
|
|
targetVersion,
|
|
allowCanaryLatest,
|
|
}) {
|
|
const problems = [];
|
|
const distTags = packageDoc["dist-tags"] ?? {};
|
|
const taggedVersion = distTags[distTag];
|
|
|
|
if (taggedVersion !== targetVersion) {
|
|
problems.push(
|
|
createProblem(
|
|
`${packageName}: dist-tag ${distTag} resolves to ${taggedVersion ?? "<missing>"}, expected ${targetVersion}`,
|
|
),
|
|
);
|
|
}
|
|
|
|
const targetManifest = requireManifest(packageName, targetVersion, packageDoc, packageManifestsByKey, problems);
|
|
if (targetManifest) {
|
|
for (const problem of collectInternalDependencyProblemEntries(
|
|
targetManifest,
|
|
packageDocsByName,
|
|
packageManifestsByKey,
|
|
)) {
|
|
problems.push(createProblem(`${packageName}@${targetVersion}: ${problem.message}`, problem));
|
|
}
|
|
}
|
|
|
|
if (PRERELEASE_CHANNELS.has(channel)) {
|
|
const latestVersion = distTags.latest;
|
|
|
|
if (latestVersion && isPrereleaseVersion(latestVersion) && !allowCanaryLatest) {
|
|
problems.push(
|
|
createProblem(
|
|
`${packageName}: latest dist-tag still resolves to prerelease ${latestVersion}; if that state is intentional, rerun the verification script directly with --allow-canary-latest`,
|
|
{ retriable: false },
|
|
),
|
|
);
|
|
}
|
|
|
|
if (latestVersion && isPrereleaseVersion(latestVersion)) {
|
|
const latestManifest = requireManifest(
|
|
packageName,
|
|
latestVersion,
|
|
packageDoc,
|
|
packageManifestsByKey,
|
|
problems,
|
|
);
|
|
if (latestManifest) {
|
|
for (const problem of collectInternalDependencyProblemEntries(
|
|
latestManifest,
|
|
packageDocsByName,
|
|
packageManifestsByKey,
|
|
)) {
|
|
problems.push(createProblem(`${packageName}@${latestVersion} via latest: ${problem.message}`, problem));
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
return problems;
|
|
}
|
|
|
|
export function verifyPackageRegistryState(options) {
|
|
return verifyPackageRegistryProblems(options).map((problem) => problem.message);
|
|
}
|
|
|
|
function collectInternalDependencyVersions(manifest) {
|
|
const dependencyVersions = [];
|
|
|
|
for (const [sectionName, deps] of [
|
|
["dependencies", manifest.dependencies ?? {}],
|
|
["optionalDependencies", manifest.optionalDependencies ?? {}],
|
|
["peerDependencies", manifest.peerDependencies ?? {}],
|
|
]) {
|
|
for (const [dependencyName, dependencyVersion] of Object.entries(deps)) {
|
|
if (!dependencyName.startsWith("@paperclipai/")) {
|
|
continue;
|
|
}
|
|
|
|
if (typeof dependencyVersion !== "string" || !dependencyVersion) {
|
|
continue;
|
|
}
|
|
|
|
if (sectionName === "peerDependencies" && isRangeVersionSpecifier(dependencyVersion)) {
|
|
continue;
|
|
}
|
|
|
|
dependencyVersions.push({
|
|
packageName: dependencyName,
|
|
version: dependencyVersion,
|
|
});
|
|
}
|
|
}
|
|
|
|
return dependencyVersions;
|
|
}
|
|
|
|
async function main() {
|
|
const options = parseArgs(process.argv.slice(2));
|
|
const packageNames = [...new Set(options.packages)];
|
|
const packageDocsByName = new Map();
|
|
const packageManifestsByKey = new Map();
|
|
|
|
await Promise.all(
|
|
packageNames.map(async (packageName) => {
|
|
packageDocsByName.set(packageName, await fetchPackageDocument(packageName));
|
|
}),
|
|
);
|
|
|
|
const versionsToFetchByPackage = new Map();
|
|
for (const packageName of packageNames) {
|
|
const packageDoc = packageDocsByName.get(packageName);
|
|
const versionsToFetch = new Set([options.targetVersion]);
|
|
const latestVersion = packageDoc?.["dist-tags"]?.latest;
|
|
if (latestVersion && isCanaryVersion(latestVersion)) {
|
|
versionsToFetch.add(latestVersion);
|
|
}
|
|
versionsToFetchByPackage.set(packageName, versionsToFetch);
|
|
}
|
|
|
|
await Promise.all(
|
|
[...versionsToFetchByPackage.entries()].flatMap(([packageName, versionsToFetch]) =>
|
|
[...versionsToFetch].map(async (version) => {
|
|
packageManifestsByKey.set(
|
|
createManifestLookupKey(packageName, version),
|
|
await fetchPackageManifest(packageName, version, { allowMissing: true }),
|
|
);
|
|
}),
|
|
),
|
|
);
|
|
|
|
const dependencyVersionsByKey = new Map();
|
|
for (const [packageName, versionsToFetch] of versionsToFetchByPackage.entries()) {
|
|
for (const version of versionsToFetch) {
|
|
const manifest = resolvePublishedManifest(
|
|
packageName,
|
|
version,
|
|
packageDocsByName.get(packageName),
|
|
packageManifestsByKey,
|
|
);
|
|
if (!manifest) {
|
|
continue;
|
|
}
|
|
|
|
for (const dependencyVersion of collectInternalDependencyVersions(manifest)) {
|
|
dependencyVersionsByKey.set(
|
|
createManifestLookupKey(dependencyVersion.packageName, dependencyVersion.version),
|
|
dependencyVersion,
|
|
);
|
|
}
|
|
}
|
|
}
|
|
|
|
await Promise.all(
|
|
[...dependencyVersionsByKey.values()].map(async ({ packageName, version }) => {
|
|
const lookupKey = createManifestLookupKey(packageName, version);
|
|
if (packageManifestsByKey.has(lookupKey)) {
|
|
return;
|
|
}
|
|
|
|
packageManifestsByKey.set(
|
|
lookupKey,
|
|
await fetchPackageManifest(packageName, version, { allowMissing: true }),
|
|
);
|
|
}),
|
|
);
|
|
|
|
const problems = [];
|
|
|
|
for (const packageName of packageNames) {
|
|
process.stdout.write(` Verifying ${packageName} on dist-tag ${options.distTag}\n`);
|
|
const packageProblems = verifyPackageRegistryProblems({
|
|
packageName,
|
|
packageDoc: packageDocsByName.get(packageName),
|
|
packageDocsByName,
|
|
packageManifestsByKey,
|
|
channel: options.channel,
|
|
distTag: options.distTag,
|
|
targetVersion: options.targetVersion,
|
|
allowCanaryLatest: options.allowCanaryLatest,
|
|
});
|
|
|
|
if (packageProblems.length === 0) {
|
|
process.stdout.write(` ✓ dist-tag and published internal dependencies are consistent\n`);
|
|
continue;
|
|
}
|
|
|
|
for (const problem of packageProblems) {
|
|
process.stderr.write(` ✗ ${problem.message}\n`);
|
|
problems.push(problem);
|
|
}
|
|
}
|
|
|
|
if (problems.length > 0) {
|
|
const exitCode = problems.some((problem) => !problem.retriable)
|
|
? EXIT_NON_RETRIABLE_FAILURE
|
|
: EXIT_RETRIABLE_FAILURE;
|
|
throw createExitError(`npm registry verification failed for ${problems.length} problem(s)`, exitCode);
|
|
}
|
|
}
|
|
|
|
const isDirectRun = process.argv[1] && import.meta.url === pathToFileURL(process.argv[1]).href;
|
|
|
|
if (isDirectRun) {
|
|
main().catch((error) => {
|
|
process.stderr.write(`Error: ${error.message}\n`);
|
|
process.exit(error.exitCode ?? EXIT_RETRIABLE_FAILURE);
|
|
});
|
|
}
|