mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-02 02:07:25 +08:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The release system publishes ~33 public npm packages per release across the canary, nightly, beta, and stable channels > - `scripts/release.sh` publishes them strictly sequentially: publish one package, poll npm until that version is registry-visible, then start the next > - npm accepts a publish in seconds, but registry packument propagation can lag minutes per package (the CI budget was raised to 30 minutes per package after two aborted releases), so the total publish time is the sum of every package's lag — about two hours on a bad npm day, paid by every channel run including every canary on every master push > - This pull request keeps the publishes sequential but runs all the registry visibility polls concurrently once every publish is accepted > - The benefit is that the wall-clock cost of npm propagation drops from the sum of all packages' lag to the single slowest package's lag, with every existing safety property preserved ## Linked Issues or Issue Description No existing issue. Description follows the enhancement template: **What existing behavior does this improve?** The npm publish step of `scripts/release.sh` (Step 5), used by every release channel. **Subsystem affected** Release tooling (`scripts/release.sh`, `scripts/release-lib.sh`). **Current behavior** Packages publish one at a time, and after each publish the script polls npm until that package's version is visible in the registry packument before publishing the next. With per-package propagation lag of minutes (observed up to ~15 minutes; per-package CI budget is 30 minutes), the full 33-package set takes up to ~2 hours of mostly idle waiting. **Proposed behavior** Phase 1 publishes every package sequentially exactly as today (a rejected publish still aborts the batch immediately with exact attribution). Phase 2 then polls registry visibility for all packages concurrently. Each package keeps its own `NPM_PUBLISH_VERIFY_ATTEMPTS` × `NPM_PUBLISH_VERIFY_DELAY_SECONDS` budget, and any version that never becomes visible still hard-fails the release, now naming every straggler. **Reason and benefit** Total publish wait becomes the slowest single package's lag instead of the sum of all lags — typically minutes instead of hours. This shortens every canary, nightly, beta, and stable run and reduces exposure to job timeouts during npm slowdowns. **Breaking changes** None. Dry-run output is byte-identical in structure, dist-tags are still applied at publish time (`--tag`), the Sigstore TLOG duplicate-recovery path is untouched, and the later dist-tag integrity check (`wait_for_release_registry_state`) is unchanged. ## What Changed - `scripts/release-lib.sh`: replaced `publish_package_to_npm_and_wait` with `wait_for_npm_package_versions`, which takes the package tuple list and polls every package's visibility in background subshells, each reusing the existing `wait_for_npm_package_version` poll (same per-package budget), then reports per-package success or fails naming all stragglers - `scripts/release.sh` Step 5: the publish loop calls `publish_package_to_npm` only (sequential, fail-fast on a rejected publish), followed by one call to `wait_for_npm_package_versions` for the whole set; Step 6's recap line updated to match - `scripts/release-lib.test.mjs`: the registry-visibility and workflow-budget tests now drive the new function (same assertions on `npm view` counts, virtual sleeps, and the fail-closed message, which now names the straggler); a new cross-visibility test proves concurrency — two fake packages that each become visible only after the other has been polled can only converge when polled in parallel, so the test fails if the waits ever serialize again Safety analysis for the ordering change: nothing in the publish loop resolves sibling packages from the registry. `prepare-bundled-package.mjs` bundles and patches from the local workspace tree, and the TLOG duplicate-recovery path only queries the package it just published. The only consumer of the "visible before next publish" invariant was the release script's own final verification, which still runs against the full set. ## Verification - `node --test scripts/release-lib.test.mjs` — 15 tests pass, including the new concurrency proof and the existing 15-minute-20-second budget tolerance test against the new function - `npm run test:release-registry` — full lane, 140 tests pass - `bash -n` on both scripts; `shellcheck` reports no findings beyond the three pre-existing ones on master (verified by comparing counts against `origin/master` copies) - A real-release exercise happens on the next master push: every canary run executes this exact path ## Risks - Low. The failure mode most worth watching is a release where some packages become visible and others never do: previously the run stopped at the first invisible package with later packages unpublished; now all packages are accepted before visibility is enforced, and the run fails naming every straggler. Recovery is identical in both worlds (the next attempt derives a new version number), and the accepted-but-lagging packages carry the correct dist-tag either way. - Publish jobs run the source commit's copy of `release.sh`, so this change takes effect for a given channel only once its source commit includes this merge — promoted nightlies/betas cut from older commits keep the old sequential behavior until their trains catch up. ## Model Used Claude Fable 5 (`claude-fable-5`), extended thinking with tool use (Claude Code). ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge
608 lines
16 KiB
Bash
608 lines
16 KiB
Bash
#!/usr/bin/env bash
|
|
|
|
if [ -z "${REPO_ROOT:-}" ]; then
|
|
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
|
fi
|
|
|
|
release_info() {
|
|
echo "$@"
|
|
}
|
|
|
|
release_warn() {
|
|
echo "Warning: $*" >&2
|
|
}
|
|
|
|
release_fail() {
|
|
echo "Error: $*" >&2
|
|
exit 1
|
|
}
|
|
|
|
git_remote_exists() {
|
|
git -C "$REPO_ROOT" remote get-url "$1" >/dev/null 2>&1
|
|
}
|
|
|
|
github_repo_from_remote() {
|
|
local remote_url
|
|
|
|
remote_url="$(git -C "$REPO_ROOT" remote get-url "$1" 2>/dev/null || true)"
|
|
[ -n "$remote_url" ] || return 1
|
|
|
|
remote_url="${remote_url%.git}"
|
|
remote_url="${remote_url#ssh://}"
|
|
|
|
node - "$remote_url" <<'NODE'
|
|
const remoteUrl = process.argv[2];
|
|
|
|
const patterns = [
|
|
/^https?:\/\/github\.com\/([^/]+\/[^/]+)$/,
|
|
/^git@github\.com:([^/]+\/[^/]+)$/,
|
|
/^[^:]+:([^/]+\/[^/]+)$/
|
|
];
|
|
|
|
for (const pattern of patterns) {
|
|
const match = remoteUrl.match(pattern);
|
|
if (!match) continue;
|
|
process.stdout.write(match[1]);
|
|
process.exit(0);
|
|
}
|
|
|
|
process.exit(1);
|
|
NODE
|
|
}
|
|
|
|
resolve_release_remote() {
|
|
local remote="${RELEASE_REMOTE:-${PUBLISH_REMOTE:-}}"
|
|
|
|
if [ -n "$remote" ]; then
|
|
git_remote_exists "$remote" || release_fail "git remote '$remote' does not exist."
|
|
printf '%s\n' "$remote"
|
|
return
|
|
fi
|
|
|
|
if git_remote_exists public-gh; then
|
|
printf 'public-gh\n'
|
|
return
|
|
fi
|
|
|
|
if git_remote_exists public; then
|
|
printf 'public\n'
|
|
return
|
|
fi
|
|
|
|
if git_remote_exists origin; then
|
|
printf 'origin\n'
|
|
return
|
|
fi
|
|
|
|
release_fail "no git remote found. Configure RELEASE_REMOTE or PUBLISH_REMOTE."
|
|
}
|
|
|
|
fetch_release_remote() {
|
|
git -C "$REPO_ROOT" fetch "$1" --prune --tags
|
|
}
|
|
|
|
git_current_branch() {
|
|
git -C "$REPO_ROOT" symbolic-ref --quiet --short HEAD 2>/dev/null || true
|
|
}
|
|
|
|
git_local_tag_exists() {
|
|
git -C "$REPO_ROOT" show-ref --verify --quiet "refs/tags/$1"
|
|
}
|
|
|
|
git_remote_tag_exists() {
|
|
git -C "$REPO_ROOT" ls-remote --exit-code --tags "$2" "refs/tags/$1" >/dev/null 2>&1
|
|
}
|
|
|
|
get_last_stable_tag() {
|
|
git -C "$REPO_ROOT" tag --list 'v*' --sort=-version:refname | head -1
|
|
}
|
|
|
|
get_current_stable_version() {
|
|
local tag
|
|
tag="$(get_last_stable_tag)"
|
|
if [ -z "$tag" ]; then
|
|
printf '0.0.0\n'
|
|
else
|
|
printf '%s\n' "${tag#v}"
|
|
fi
|
|
}
|
|
|
|
stable_version_slot_for_date() {
|
|
node - "${1:-}" <<'NODE'
|
|
const input = process.argv[2];
|
|
|
|
const date = input ? new Date(`${input}T00:00:00Z`) : new Date();
|
|
if (Number.isNaN(date.getTime())) {
|
|
console.error(`invalid date: ${input}`);
|
|
process.exit(1);
|
|
}
|
|
|
|
const month = String(date.getUTCMonth() + 1);
|
|
const day = String(date.getUTCDate()).padStart(2, '0');
|
|
|
|
process.stdout.write(`${date.getUTCFullYear()}.${month}${day}`);
|
|
NODE
|
|
}
|
|
|
|
utc_date_iso() {
|
|
node <<'NODE'
|
|
const date = new Date();
|
|
const y = date.getUTCFullYear();
|
|
const m = String(date.getUTCMonth() + 1).padStart(2, '0');
|
|
const d = String(date.getUTCDate()).padStart(2, '0');
|
|
process.stdout.write(`${y}-${m}-${d}`);
|
|
NODE
|
|
}
|
|
|
|
next_stable_version() {
|
|
local release_date="$1"
|
|
shift
|
|
|
|
node - "$release_date" "$@" <<'NODE'
|
|
const input = process.argv[2];
|
|
const packageNames = process.argv.slice(3);
|
|
const { execSync } = require("node:child_process");
|
|
const { readFileSync } = require("node:fs");
|
|
|
|
const date = input ? new Date(`${input}T00:00:00Z`) : new Date();
|
|
if (Number.isNaN(date.getTime())) {
|
|
console.error(`invalid date: ${input}`);
|
|
process.exit(1);
|
|
}
|
|
|
|
// Optional pre-fetched version data (see release-registry-versions.mjs).
|
|
// Avoids one serial `npm view` round-trip per package.
|
|
let versionsCache = null;
|
|
if (process.env.RELEASE_PACKAGE_VERSIONS_FILE) {
|
|
try {
|
|
versionsCache = JSON.parse(readFileSync(process.env.RELEASE_PACKAGE_VERSIONS_FILE, "utf8"));
|
|
} catch {
|
|
versionsCache = null;
|
|
}
|
|
}
|
|
|
|
const stableSlot = `${date.getUTCFullYear()}.${date.getUTCMonth() + 1}${String(date.getUTCDate()).padStart(2, "0")}`;
|
|
const pattern = new RegExp(`^${stableSlot.replace(/\./g, '\\.')}\.(\\d+)$`);
|
|
let max = -1;
|
|
|
|
for (const packageName of packageNames) {
|
|
let versions = [];
|
|
|
|
if (versionsCache && Array.isArray(versionsCache[packageName])) {
|
|
versions = versionsCache[packageName];
|
|
} else {
|
|
try {
|
|
const raw = execSync(`npm view ${JSON.stringify(packageName)} versions --json`, {
|
|
encoding: "utf8",
|
|
stdio: ["ignore", "pipe", "ignore"],
|
|
}).trim();
|
|
|
|
if (raw) {
|
|
const parsed = JSON.parse(raw);
|
|
versions = Array.isArray(parsed) ? parsed : [parsed];
|
|
}
|
|
} catch {
|
|
versions = [];
|
|
}
|
|
}
|
|
|
|
for (const version of versions) {
|
|
const match = version.match(pattern);
|
|
if (!match) continue;
|
|
max = Math.max(max, Number(match[1]));
|
|
}
|
|
}
|
|
|
|
process.stdout.write(`${stableSlot}.${max + 1}`);
|
|
NODE
|
|
}
|
|
|
|
require_prerelease_channel() {
|
|
case "$1" in
|
|
canary|nightly|beta) ;;
|
|
*) release_fail "unknown prerelease channel: $1" ;;
|
|
esac
|
|
}
|
|
|
|
next_prerelease_version() {
|
|
local channel="$1"
|
|
local stable_version="$2"
|
|
shift 2
|
|
|
|
require_prerelease_channel "$channel"
|
|
|
|
node - "$channel" "$stable_version" "$@" <<'NODE'
|
|
const channel = process.argv[2];
|
|
const stable = process.argv[3];
|
|
const packageNames = process.argv.slice(4);
|
|
const { execSync } = require("node:child_process");
|
|
const { readFileSync } = require("node:fs");
|
|
|
|
// Optional pre-fetched version data (see release-registry-versions.mjs).
|
|
// Avoids one serial `npm view` round-trip per package.
|
|
let versionsCache = null;
|
|
if (process.env.RELEASE_PACKAGE_VERSIONS_FILE) {
|
|
try {
|
|
versionsCache = JSON.parse(readFileSync(process.env.RELEASE_PACKAGE_VERSIONS_FILE, "utf8"));
|
|
} catch {
|
|
versionsCache = null;
|
|
}
|
|
}
|
|
|
|
const pattern = new RegExp(`^${stable.replace(/\./g, '\\.')}-${channel}\\.(\\d+)$`);
|
|
let max = -1;
|
|
|
|
for (const packageName of packageNames) {
|
|
let versions = [];
|
|
|
|
if (versionsCache && Array.isArray(versionsCache[packageName])) {
|
|
versions = versionsCache[packageName];
|
|
} else {
|
|
try {
|
|
const raw = execSync(`npm view ${JSON.stringify(packageName)} versions --json`, {
|
|
encoding: "utf8",
|
|
stdio: ["ignore", "pipe", "ignore"],
|
|
}).trim();
|
|
|
|
if (raw) {
|
|
const parsed = JSON.parse(raw);
|
|
versions = Array.isArray(parsed) ? parsed : [parsed];
|
|
}
|
|
} catch {
|
|
versions = [];
|
|
}
|
|
}
|
|
|
|
for (const version of versions) {
|
|
const match = version.match(pattern);
|
|
if (!match) continue;
|
|
max = Math.max(max, Number(match[1]));
|
|
}
|
|
}
|
|
|
|
process.stdout.write(`${stable}-${channel}.${max + 1}`);
|
|
NODE
|
|
}
|
|
|
|
next_canary_version() {
|
|
local stable_version="$1"
|
|
shift
|
|
next_prerelease_version canary "$stable_version" "$@"
|
|
}
|
|
|
|
release_notes_file() {
|
|
printf '%s/releases/v%s.md\n' "$REPO_ROOT" "$1"
|
|
}
|
|
|
|
stable_tag_name() {
|
|
printf 'v%s\n' "$1"
|
|
}
|
|
|
|
prerelease_tag_name() {
|
|
require_prerelease_channel "$1"
|
|
printf '%s/v%s\n' "$1" "$2"
|
|
}
|
|
|
|
canary_tag_name() {
|
|
prerelease_tag_name canary "$1"
|
|
}
|
|
|
|
npm_package_version_exists() {
|
|
local package_name="$1"
|
|
local version="$2"
|
|
local resolved
|
|
|
|
resolved="$(npm view "${package_name}@${version}" version 2>/dev/null || true)"
|
|
[ "$resolved" = "$version" ]
|
|
}
|
|
|
|
wait_for_npm_package_version() {
|
|
local package_name="$1"
|
|
local version="$2"
|
|
local attempts="${3:-12}"
|
|
local delay_seconds="${4:-5}"
|
|
local attempt=1
|
|
|
|
while [ "$attempt" -le "$attempts" ]; do
|
|
if npm_package_version_exists "$package_name" "$version"; then
|
|
return 0
|
|
fi
|
|
|
|
if [ "$attempt" -lt "$attempts" ]; then
|
|
sleep "$delay_seconds"
|
|
fi
|
|
attempt=$((attempt + 1))
|
|
done
|
|
|
|
return 1
|
|
}
|
|
|
|
is_npm_tlog_duplicate_error() {
|
|
local output="$1"
|
|
|
|
grep -q "TLOG_CREATE_ENTRY_ERROR" <<< "$output" &&
|
|
grep -q "equivalent entry already exists in the transparency log" <<< "$output"
|
|
}
|
|
|
|
package_publish_tool() {
|
|
node -e '
|
|
const pkg = require(process.cwd() + "/package.json");
|
|
const bundled = pkg.bundleDependencies ?? pkg.bundledDependencies ?? [];
|
|
process.stdout.write(bundled.length > 0 ? "npm" : "pnpm");
|
|
'
|
|
}
|
|
|
|
BUNDLED_NPM_PACK_VERSION="10.9.7"
|
|
BUNDLED_NPM_PUBLISH_VERSION="11.18.0"
|
|
|
|
run_bundled_npm_pack() {
|
|
npx --yes "npm@$BUNDLED_NPM_PACK_VERSION" "$@" --ignore-scripts
|
|
}
|
|
|
|
run_bundled_npm_publish() {
|
|
npx --yes "npm@$BUNDLED_NPM_PUBLISH_VERSION" "$@" --ignore-scripts --loglevel verbose
|
|
}
|
|
|
|
run_package_publish() {
|
|
local publish_tool="$1"
|
|
local dist_tag="$2"
|
|
local disable_provenance="${3:-false}"
|
|
|
|
if [ "$publish_tool" = "npm" ]; then
|
|
if [ "$disable_provenance" = "true" ]; then
|
|
run_bundled_npm_publish publish --tag "$dist_tag" --access public --provenance=false
|
|
else
|
|
run_bundled_npm_publish publish --tag "$dist_tag" --access public
|
|
fi
|
|
return
|
|
fi
|
|
|
|
if [ "$disable_provenance" = "true" ]; then
|
|
pnpm publish --no-git-checks --tag "$dist_tag" --access public --provenance=false
|
|
else
|
|
pnpm publish --no-git-checks --tag "$dist_tag" --access public
|
|
fi
|
|
}
|
|
|
|
publish_package_to_npm() {
|
|
local dist_tag="$1"
|
|
local package_name="$2"
|
|
local package_version="$3"
|
|
local publish_tool="${4:-pnpm}"
|
|
local publish_log
|
|
|
|
publish_log="$(mktemp "${TMPDIR:-/tmp}/paperclip-npm-publish.XXXXXX")"
|
|
|
|
if (set -o pipefail; run_package_publish "$publish_tool" "$dist_tag" false 2>&1 | tee "$publish_log"); then
|
|
rm -f "$publish_log"
|
|
return 0
|
|
fi
|
|
|
|
if ! is_npm_tlog_duplicate_error "$(cat "$publish_log")"; then
|
|
rm -f "$publish_log"
|
|
return 1
|
|
fi
|
|
|
|
release_warn "npm publish hit a duplicate Sigstore transparency-log entry for ${package_name}@${package_version}."
|
|
|
|
if npm_package_version_exists "$package_name" "$package_version"; then
|
|
release_warn "npm already exposes ${package_name}@${package_version}; continuing to registry verification."
|
|
rm -f "$publish_log"
|
|
return 0
|
|
fi
|
|
|
|
case "$dist_tag" in
|
|
canary|nightly) ;;
|
|
*)
|
|
release_warn "Not retrying ${package_name}@${package_version} without provenance for dist-tag ${dist_tag}."
|
|
rm -f "$publish_log"
|
|
return 1
|
|
;;
|
|
esac
|
|
|
|
release_warn "Retrying ${package_name}@${package_version} once with npm provenance disabled."
|
|
if run_package_publish "$publish_tool" "$dist_tag" true; then
|
|
rm -f "$publish_log"
|
|
return 0
|
|
fi
|
|
|
|
rm -f "$publish_log"
|
|
return 1
|
|
}
|
|
|
|
# Wait for every already-published package to become registry-visible,
|
|
# polling all of them concurrently. npm accepts a publish in seconds, but
|
|
# packument propagation through the registry CDN can lag minutes per package;
|
|
# waiting on each package before publishing the next made the total wait the
|
|
# SUM of every package's lag (~2 hours on a bad day for the full set). Every
|
|
# publish has already been accepted by the time this runs, so the polls can
|
|
# race: the wall-clock cost becomes the single slowest package's lag. Each
|
|
# package keeps its own attempts x delay budget, and a package that never
|
|
# becomes visible still fails the release, naming every straggler.
|
|
#
|
|
# $3 is the list_public_package_info tuple list (pkg_dir<TAB>name<TAB>version
|
|
# lines); the directory field is ignored.
|
|
wait_for_npm_package_versions() {
|
|
local attempts="${1:-12}"
|
|
local delay_seconds="${2:-5}"
|
|
local package_info="$3"
|
|
|
|
# The polling phase runs in a subshell that owns its own EXIT trap: a
|
|
# cancelled or signalled release reaps every in-flight poller and the
|
|
# scratch directory instead of leaking one npm poll per package for the
|
|
# rest of its budget. The subshell also keeps this trap from clobbering
|
|
# the caller's cleanup trap.
|
|
(
|
|
local status_dir
|
|
local pids=()
|
|
local specs=()
|
|
local failures=()
|
|
local index=0
|
|
local pkg_name
|
|
local pkg_version
|
|
local i
|
|
|
|
status_dir="$(mktemp -d "${TMPDIR:-/tmp}/paperclip-release-visibility.XXXXXX")"
|
|
|
|
# shellcheck disable=SC2329 # invoked via the trap below
|
|
reap_visibility_pollers() {
|
|
local pid
|
|
for pid in ${pids[@]+"${pids[@]}"}; do
|
|
kill "$pid" 2>/dev/null || true
|
|
done
|
|
rm -rf "$status_dir"
|
|
}
|
|
trap reap_visibility_pollers EXIT INT TERM
|
|
|
|
while IFS=$'\t' read -r _pkg_dir pkg_name pkg_version; do
|
|
[ -z "$pkg_name" ] && continue
|
|
(
|
|
if wait_for_npm_package_version "$pkg_name" "$pkg_version" "$attempts" "$delay_seconds"; then
|
|
: > "$status_dir/$index.ok"
|
|
fi
|
|
) &
|
|
pids+=("$!")
|
|
specs+=("${pkg_name}@${pkg_version}")
|
|
index=$((index + 1))
|
|
done <<< "$package_info"
|
|
|
|
if [ "${#pids[@]}" -gt 0 ]; then
|
|
for i in "${!pids[@]}"; do
|
|
wait "${pids[$i]}" || true
|
|
if [ -e "$status_dir/$i.ok" ]; then
|
|
release_info " ✓ ${specs[$i]} is registry-visible"
|
|
else
|
|
failures+=("${specs[$i]}")
|
|
fi
|
|
done
|
|
fi
|
|
|
|
if [ "${#failures[@]}" -gt 0 ]; then
|
|
release_warn "npm accepted every publish, but these versions did not become registry-visible: ${failures[*]}"
|
|
exit 1
|
|
fi
|
|
|
|
exit 0
|
|
)
|
|
}
|
|
|
|
verify_npm_installable() {
|
|
local package_spec="$1"
|
|
local expected_version="$2"
|
|
local install_dir
|
|
local installed_version
|
|
|
|
install_dir="$(mktemp -d "${TMPDIR:-/tmp}/paperclip-release-install.XXXXXX")"
|
|
|
|
if ! npm install --prefix "$install_dir" "$package_spec" --no-audit --no-fund; then
|
|
rm -rf "$install_dir"
|
|
return 1
|
|
fi
|
|
|
|
installed_version="$(node -e "console.log(require(process.argv[1]).version)" "$install_dir/node_modules/paperclipai/package.json")"
|
|
rm -rf "$install_dir"
|
|
|
|
[ "$installed_version" = "$expected_version" ]
|
|
}
|
|
|
|
wait_for_release_registry_state() {
|
|
local attempts="${1:-12}"
|
|
local delay_seconds="${2:-5}"
|
|
shift 2
|
|
local attempt=1
|
|
local output
|
|
local status
|
|
|
|
while [ "$attempt" -le "$attempts" ]; do
|
|
if output="$(node "$REPO_ROOT/scripts/verify-release-registry-state.mjs" "$@" 2>&1)"; then
|
|
[ -n "$output" ] && printf '%s\n' "$output"
|
|
return 0
|
|
fi
|
|
status=$?
|
|
|
|
printf '%s\n' "$output" >&2
|
|
|
|
if [ "$status" -eq 2 ]; then
|
|
return "$status"
|
|
fi
|
|
|
|
if [ "$attempt" -lt "$attempts" ]; then
|
|
release_warn "npm registry metadata has not converged yet (attempt ${attempt}/${attempts}); retrying in ${delay_seconds}s."
|
|
sleep "$delay_seconds"
|
|
fi
|
|
|
|
attempt=$((attempt + 1))
|
|
done
|
|
|
|
return "${status:-1}"
|
|
}
|
|
|
|
require_clean_worktree() {
|
|
if [ -n "$(git -C "$REPO_ROOT" status --porcelain)" ]; then
|
|
release_fail "working tree is not clean. Commit, stash, or remove changes before releasing."
|
|
fi
|
|
}
|
|
|
|
require_on_master_branch() {
|
|
local current_branch
|
|
current_branch="$(git_current_branch)"
|
|
if [ "$current_branch" != "master" ]; then
|
|
release_fail "this release step must run from branch master, but current branch is ${current_branch:-<detached>}."
|
|
fi
|
|
}
|
|
|
|
# Promotion channels only republish commits that already shipped on the
|
|
# previous lane, so the source commit must carry that lane's release tag.
|
|
require_channel_tag_at_head() {
|
|
local channel="$1"
|
|
|
|
require_prerelease_channel "$channel"
|
|
|
|
if ! git -C "$REPO_ROOT" tag --points-at HEAD | grep -q "^${channel}/v"; then
|
|
release_fail "HEAD has no ${channel}/v* tag; this channel only publishes commits that already shipped a ${channel} release."
|
|
fi
|
|
}
|
|
|
|
# The inverse guard: a commit ships on a promotion channel at most once, so
|
|
# concurrent or repeated runs cannot double-publish it. Delete the lane tag
|
|
# first if a republish is genuinely intended.
|
|
require_channel_tag_absent_at_head() {
|
|
local channel="$1"
|
|
local existing
|
|
|
|
require_prerelease_channel "$channel"
|
|
|
|
existing="$(git -C "$REPO_ROOT" tag --points-at HEAD | grep "^${channel}/v" | head -1 || true)"
|
|
if [ -n "$existing" ]; then
|
|
release_fail "HEAD already shipped as ${existing}; delete that tag first if you really want to republish this commit on the ${channel} channel."
|
|
fi
|
|
}
|
|
|
|
require_npm_publish_auth() {
|
|
local dry_run="$1"
|
|
|
|
if [ "$dry_run" = true ]; then
|
|
return
|
|
fi
|
|
|
|
if npm whoami >/dev/null 2>&1; then
|
|
release_info " ✓ Logged in to npm as $(npm whoami)"
|
|
return
|
|
fi
|
|
|
|
if [ "${GITHUB_ACTIONS:-}" = "true" ]; then
|
|
release_info " ✓ npm publish auth will be provided by GitHub Actions trusted publishing"
|
|
return
|
|
fi
|
|
|
|
release_fail "npm publish auth is not available. Use 'npm login' locally or run from GitHub Actions with trusted publishing."
|
|
}
|
|
|
|
list_public_package_info() {
|
|
node "$REPO_ROOT/scripts/release-package-map.mjs" list
|
|
}
|
|
|
|
set_public_package_version() {
|
|
node "$REPO_ROOT/scripts/release-package-map.mjs" set-version "$1"
|
|
}
|