Skip to content

Simplify releases with generated build artifacts and one retained tarball - #20

Open
justjam2013 wants to merge 6 commits into
mainfrom
codex/simplify-release
Open

justjam2013 wants to merge 6 commits into
mainfrom
codex/simplify-release

Conversation

@justjam2013

@justjam2013 justjam2013 commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Problem and resulting behavior

binding.js is now an ignored build/package artifact, generated automatically alongside every native prebuild. Version PRs update only authoritative version sources; no committed loader can become stale.

Changes

  • npm run prepare-version -- 1.0.1 updates package.json, both root package-lock.json versions, Cargo.toml, and the root Cargo.lock package. It requires only Node and does not build, stage, commit, tag, or publish.
  • Local development: npm ci, npm run build, then npm test and npm run test:release. Every build generates the loader and host binary with pinned napi-rs and locked Cargo dependencies. Rebuild after source/version changes; never edit or commit binding.js.
  • Remove tracked binding.js, committed-loader comparison/diff logic, build:check, obsolete generated tests, and loader generation/failure handling from prepare-version. The final tooling has 10 script files (down from the original 15) and 7 npm commands. This artifact-model update removes 883 net lines.
  • All eight native builds use the normal build command. Assembly deterministically copies the platform-independent loader from the same run's Linux x64 glibc artifact and all eight binaries, packs once, and verifies the packed loader/binary bytes against those tested inputs.
  • Retained-tarball validation works without a source-checkout loader. Explicit package files include binding.js despite .gitignore. Plain npm pack does not build; complete packaging uses node scripts/assemble.js with all eight same-commit artifacts.
  • README and release/platform docs explain automatic generation, local build/test behavior, and the simplified version flow.

Preserved safeguards

Eight native builds and 24 retained-tarball installs on Node 22/24/26; one tarball plus SHA-512; CJS/ESM/API, real ICMP, resource and actual-libc tests; Trusted Publishing/OIDC/provenance/public access; npm-production; latest/next policy; non-cancelling publication concurrency; absolute tarball path; at-most-once npm publish; bounded registry visibility retries. Publisher code and publish workflow are unchanged by the artifact-model update. No stale-file detection, repair, auto-commit, or version-triggered generation.

Validation

At d2e2c44:

  • All 33 CI checks passed in nonpublishing run 37046038742: eight native builds, assembly/tooling, and 24 retained-tarball installs.
  • Local: 134 tooling tests, 19 Rust tests, formatting, Clippy with warnings denied, actionlint, and git diff checks pass.
  • Normal native macOS ARM64 build succeeds with binding.js absent; all 5 CJS/ESM/API tests pass.
  • Disposable npm run prepare-version -- 1.0.1 without installed dependencies changes only the four version files. A subsequent normal build generates the 1.0.1 loader and passes all 5 API tests. The manifest version also overrides an unrelated inherited npm_new_version.
  • Packaging tests cover ignored loader inclusion, absent/empty loaders, assembly without a source loader, and downloaded-tarball validation without a source loader.
  • Local privileged tests required a sudo password; CI supplies the all-platform runtime coverage.

No merge, npm publication, tag/release changes, or release workflow dispatch. Repository version remains 1.0.0.

@justjam2013 justjam2013 changed the title Simplify release tooling to reviewed loaders and one retained tarball Simplify releases with generated build artifacts and one retained tarball Oct 2, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant