mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work. > - The release subsystem publishes the public workspace packages and also powers release-related CI validation. > - The release flow currently asks npm for package versions one package at a time in multiple places. > - That serial registry latency slows the PR Canary Dry Run path and real release invocations even though the checks are independent. > - This pull request batches npm registry version lookups with bounded concurrency and reuses the result for version calculation. > - The benefit is shorter non-build release-script time while preserving the fresh target-version existence check before publishing. ## Linked Issues or Issue Description - No public GitHub issue exists for this release-script performance cleanup. ### Problem or motivation Release validation spends avoidable time on repeated serial `npm view` calls across the public package set. The slow path affects PR release validation and real release invocations because version discovery waits on independent registry reads one at a time. ### Proposed solution Fetch package version maps concurrently with bounded parallelism, reuse that map for stable/canary version calculation, and keep a fresh parallel absence check for the target publish version. ### Alternatives considered Keeping the existing serial shell loop is simpler, but it preserves the CI latency cost. Caching the final target-version existence check was rejected because release publish safety should still query npm freshly before publishing. ### Roadmap alignment This is a small release-tooling performance improvement. It does not duplicate any planned core product work found in `ROADMAP.md`. ## What Changed - Added `scripts/release-registry-versions.mjs` to fetch npm package version maps and assert target-version absence with bounded parallelism. - Updated `scripts/release.sh` to prefetch package versions once and to batch the final target-version absence check. - Updated `next_stable_version` and `next_canary_version` to use the prefetched version map when present, with the existing per-package npm fallback preserved. - Added release-registry helper coverage and included it in `pnpm run test:release-registry`. - Hardened the release publish helper tests so their fake `pnpm`/`npm` fixture PATH is preserved under non-login shell execution. ## Verification - `node --test scripts/release-registry-versions.test.mjs` - `pnpm run test:release-registry` - `bash -n scripts/release.sh scripts/release-lib.sh` - `git diff --check` - Safety scan before push: searched changed files for common key/token/password patterns and PII markers; only benign script-name text matched (`secrets:migrate-inline-env`). - Remote PR checks on the latest head passed, including `Typecheck + Release Registry`, `Canary Dry Run`, build, tests, e2e, policy, security scans, and commitperclip review. - Greptile reviewed the latest head with Confidence Score 5/5 and no blocking issues. ## Risks - Low risk. The release version helpers keep their original npm fallback when no prefetched version map is supplied. - The existence check remains fresh and uncached before publish, but now reports all matching package/version pairs from a parallel check. - If npm has transient failures during the prefetch step, missing or failed packages still map to an empty version list, matching the old helper behavior. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex coding agent using GPT-5, with shell/tool execution in the local repository. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [x] All Paperclip CI gates are green - [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge --------- Co-authored-by: Claude <noreply@paperclip.ing>
165 lines
5.1 KiB
JavaScript
165 lines
5.1 KiB
JavaScript
import assert from "node:assert/strict";
|
|
import { execFileSync } from "node:child_process";
|
|
import { mkdirSync, mkdtempSync, readFileSync, writeFileSync } from "node:fs";
|
|
import { tmpdir } from "node:os";
|
|
import { join } from "node:path";
|
|
import test from "node:test";
|
|
|
|
const repoRoot = new URL("..", import.meta.url).pathname.replace(/\/$/, "");
|
|
|
|
function writeExecutable(path, body) {
|
|
writeFileSync(path, body, { mode: 0o755 });
|
|
}
|
|
|
|
function runPublishHelper({ pnpmMode, npmVersionExists = false, distTag = "canary", callerPipefail = true }) {
|
|
const fixtureDir = mkdtempSync(join(tmpdir(), "paperclip-release-lib-"));
|
|
const binDir = join(fixtureDir, "bin");
|
|
const stateDir = join(fixtureDir, "state");
|
|
const callLog = join(fixtureDir, "calls.log");
|
|
mkdirSync(binDir);
|
|
mkdirSync(stateDir);
|
|
writeFileSync(callLog, "");
|
|
|
|
writeExecutable(
|
|
join(binDir, "pnpm"),
|
|
`#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
printf 'pnpm %s\\n' "$*" >> "$FAKE_CALL_LOG"
|
|
case "$PNPM_MODE" in
|
|
success)
|
|
echo "published"
|
|
exit 0
|
|
;;
|
|
tlog-then-success)
|
|
if [ ! -f "$FAKE_STATE_DIR/pnpm-called" ]; then
|
|
touch "$FAKE_STATE_DIR/pnpm-called"
|
|
echo "npm error code TLOG_CREATE_ENTRY_ERROR"
|
|
echo "npm error error creating tlog entry - (409) an equivalent entry already exists in the transparency log with UUID abc"
|
|
exit 1
|
|
fi
|
|
case " $* " in
|
|
*" --provenance=false "*)
|
|
echo "published without provenance"
|
|
exit 0
|
|
;;
|
|
*)
|
|
echo "retry did not disable provenance"
|
|
exit 1
|
|
;;
|
|
esac
|
|
;;
|
|
tlog-always-fails)
|
|
echo "npm error code TLOG_CREATE_ENTRY_ERROR"
|
|
echo "npm error error creating tlog entry - (409) an equivalent entry already exists in the transparency log with UUID abc"
|
|
exit 1
|
|
;;
|
|
non-tlog-failure)
|
|
echo "npm error code E500"
|
|
exit 1
|
|
;;
|
|
esac
|
|
exit 1
|
|
`,
|
|
);
|
|
|
|
writeExecutable(
|
|
join(binDir, "npm"),
|
|
`#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
printf 'npm %s\\n' "$*" >> "$FAKE_CALL_LOG"
|
|
if [ "$1" = "view" ] && [ "$NPM_VERSION_EXISTS" = "true" ]; then
|
|
echo "1.2.3"
|
|
exit 0
|
|
fi
|
|
exit 1
|
|
`,
|
|
);
|
|
|
|
const shellOptions = callerPipefail ? "set -euo pipefail" : "set -eu";
|
|
const script = `
|
|
${shellOptions}
|
|
source "${repoRoot}/scripts/release-lib.sh"
|
|
publish_package_to_npm ${distTag} @paperclipai/example 1.2.3
|
|
`;
|
|
|
|
let status = 0;
|
|
let output = "";
|
|
try {
|
|
output = execFileSync("bash", ["-c", script], {
|
|
cwd: fixtureDir,
|
|
encoding: "utf8",
|
|
env: {
|
|
...process.env,
|
|
PATH: `${binDir}:${process.env.PATH}`,
|
|
FAKE_CALL_LOG: callLog,
|
|
FAKE_STATE_DIR: stateDir,
|
|
NPM_VERSION_EXISTS: npmVersionExists ? "true" : "false",
|
|
PNPM_MODE: pnpmMode,
|
|
REPO_ROOT: fixtureDir,
|
|
},
|
|
stdio: ["ignore", "pipe", "pipe"],
|
|
});
|
|
} catch (error) {
|
|
status = error.status ?? 1;
|
|
output = `${error.stdout ?? ""}${error.stderr ?? ""}`;
|
|
}
|
|
|
|
return {
|
|
calls: readFileSync(callLog, "utf8"),
|
|
output,
|
|
status,
|
|
};
|
|
}
|
|
|
|
test("publish_package_to_npm returns after a successful pnpm publish", () => {
|
|
const result = runPublishHelper({ pnpmMode: "success" });
|
|
|
|
assert.equal(result.status, 0);
|
|
assert.match(result.calls, /^pnpm publish --no-git-checks --tag canary --access public$/m);
|
|
assert.doesNotMatch(result.calls, /npm view/);
|
|
assert.doesNotMatch(result.calls, /--provenance=false/);
|
|
});
|
|
|
|
test("publish_package_to_npm retries duplicate tlog failures without provenance", () => {
|
|
const result = runPublishHelper({ pnpmMode: "tlog-then-success" });
|
|
|
|
assert.equal(result.status, 0);
|
|
assert.match(result.calls, /^npm view @paperclipai\/example@1\.2\.3 version$/m);
|
|
assert.match(
|
|
result.calls,
|
|
/^pnpm publish --no-git-checks --tag canary --access public --provenance=false$/m,
|
|
);
|
|
});
|
|
|
|
test("publish_package_to_npm treats a duplicate tlog failure as complete when npm exposes the version", () => {
|
|
const result = runPublishHelper({ pnpmMode: "tlog-always-fails", npmVersionExists: true });
|
|
|
|
assert.equal(result.status, 0);
|
|
assert.match(result.calls, /^npm view @paperclipai\/example@1\.2\.3 version$/m);
|
|
assert.doesNotMatch(result.calls, /--provenance=false/);
|
|
});
|
|
|
|
test("publish_package_to_npm does not retry unrelated publish failures", () => {
|
|
const result = runPublishHelper({ pnpmMode: "non-tlog-failure" });
|
|
|
|
assert.notEqual(result.status, 0);
|
|
assert.doesNotMatch(result.calls, /npm view/);
|
|
assert.doesNotMatch(result.calls, /--provenance=false/);
|
|
});
|
|
|
|
test("publish_package_to_npm does not mask failures when caller has no pipefail", () => {
|
|
const result = runPublishHelper({ pnpmMode: "non-tlog-failure", callerPipefail: false });
|
|
|
|
assert.notEqual(result.status, 0);
|
|
assert.doesNotMatch(result.calls, /npm view/);
|
|
assert.doesNotMatch(result.calls, /--provenance=false/);
|
|
});
|
|
|
|
test("publish_package_to_npm does not retry stable publishes without provenance", () => {
|
|
const result = runPublishHelper({ pnpmMode: "tlog-then-success", distTag: "latest" });
|
|
|
|
assert.notEqual(result.status, 0);
|
|
assert.match(result.calls, /^npm view @paperclipai\/example@1\.2\.3 version$/m);
|
|
assert.doesNotMatch(result.calls, /--provenance=false/);
|
|
});
|