Skip to content

Fix npm tarball path and guard recovery of original v1.0.0 artifact - #18

Merged
justjam2013 merged 1 commit into
mainfrom
codex/npm-publication-recovery
Oct 1, 2026
Merged

justjam2013 merged 1 commit into
mainfrom
codex/npm-publication-recovery

Conversation

@justjam2013

Copy link
Copy Markdown
Collaborator

Current situation

The v1.0.0 publish job passed distribution/homebridge-node-icmp-ping-1.0.0.tgz to npm. npm interpreted it as GitHub owner/repository shorthand and attempted an SSH Git lookup. Rerunning that job would execute the broken tagged publisher again.

Proposed solution

Use path.resolve(directory, filename) so npm receives an absolute local path. Preserve all existing integrity, registry preflight/read-back, provenance, access, dist-tag and recovery checks. The regression exercises relative-directory preflight and the actual default npm writer, intercepting external execution; it fails when the old path.join line is restored.

Add a separate, narrowly pinned manual recovery job inside publish.yml, preserving Trusted Publisher workflow identity, npm-production, the npm-production-publication concurrency lock, OIDC/provenance and Node/npm versions. All original normal-release jobs are byte-for-byte unchanged. Dispatch requires current main and exact confirmation recover-v1.0.0. It cannot enter build, loader-repair, assembly or packing jobs.

Recovery pins:

  • GitHub Release 399672199, v1.0.0, stable/latest, commit 34d714b.
  • Original release run 36660590695, attempt 1, workflow 361615936; successful validation, eight builds, assembly and all 24 retained-tarball installs.
  • Original npm-distribution artifact 11073922734, archive SHA-256 a78cd6cb5e491b7298b3e0ae85a144460a8dac4f29ec5a6d60936da1c2fd29d9.

The script verifies the archive digest as a hard failure before extracting only its original tarball and integrity.json. It validates original version files, live release identity/channel, unmoved tag, main ancestry and unchanged package/version/loader inputs. It rechecks release/tag identity before registry preflight. No input can override identities or select substitute bytes; missing/expired artifacts, changed evidence and checksum failures stop without a rebuild fallback.

An existing npm version is verified without republishing only when identity, original SHA-512 and intended dist-tag match. Inconsistent state or lookup failure aborts without automatic repair. Every publication attempt retains fresh registry read-back.

Release notes

Fix local tarball publication and document recovery using the original tested artifact. No package version, native code or runtime API changes.

Additional information

Reviewed recovery procedure

After review and merge, and only when separately authorized to publish:

  1. Review current main, pinned identities and existing environment protections. Trusted Publisher must continue matching homebridge/node-icmp-ping, publish.yml, and npm-production.
  2. Run Publish GitHub Release to npm on main, entering recover-v1.0.0. This is a publication action, not a dry run.
  3. Inspect registry verification. Stop on mismatch. Do not rebuild/repack, rerun the failed release, bump versions, move/delete/recreate the release/tag or automatically repair dist-tags. Remove the narrow exception after verified recovery.

This exception avoids introducing a general historic-run publisher without a broader reviewed trust policy. Provenance identifies the recovery workflow/main commit; pinned artifact/run checks connect the published bytes to the original tested release.

Testing

  • 172 release tests passed, zero failures/skips.
  • actionlint passed for all repository workflows; git diff --check passed.
  • Restoring path.join makes the actual npm-argument regression fail.
  • Guard tests reject changed run/job/artifact evidence, expired/replaced archives and invalid dispatch identity.
  • Entry-point tests reject moved tags, recreated releases, channel drift, changed package inputs and substituted archives before registry access.
  • Verified normal-release jobs are byte-for-byte unchanged and reviewed the diff.

Live OIDC publication is intentionally unexecuted. No npm publication, recovery dispatch, failed-run rerun, release/tag mutation or merge was performed.

Reviewer nudging

Start with scripts/recover-v1.js and the separate recover-v1 job in publish.yml, then the recovery/argument regression tests and docs/releasing.md.

@justjam2013
justjam2013 merged commit ff8961d into main Oct 1, 2026
35 checks passed
@justjam2013
justjam2013 deleted the codex/npm-publication-recovery branch October 1, 2026 11:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant