## Summary - Advance the matched Pi runtime pin (`pi-ai`, `pi-coding-agent`, `pi-agent-core`, `pi-tui`) from **0.82.0 → 0.82.1** so electron-builder's production-dependency walk accepts `pi-agent-core`'s `pi-ai@^0.82.1` requirement. - Fixes the Desktop packaging PR-lane failure: `Production dependency @earendil-works/pi-ai not found for package @earendil-works/pi-agent-core` (required `^0.82.1`). - Keep the workspace override guard; update pin-policy fixtures and CLI package-config expectations. - Tighten the advisory packaging step-order test so it asserts against the real `electron-builder --dir` step (not a missing release-only step name that previously passed via `indexOf === -1`). - Run `pnpm dedupe` so the packaging lane's lockfile dedupe early-warning is clean. ## Context #2439 pinned the full Pi closure at 0.82.0 and made recent main-based packaging runs green. This advances to the current upstream patch so deploy + electron-builder stay aligned with `pi-agent-core@0.82.1`'s declared dependency range. ## Test plan - [x] `node scripts/check-pi-versions-pinned.mjs` - [x] `node --test scripts/__tests__/check-pi-versions-pinned.test.mjs` - [x] `pnpm --filter @runfusion/fusion exec vitest run src/__tests__/package-config.test.ts` - [x] `pnpm --filter @fusion/desktop exec vitest run src/__tests__/release-workflow.test.ts` - [x] `pnpm dedupe --check` - [ ] GitHub: Desktop packaging (should run full packaging walk — lockfile/package.json touched) - [ ] GitHub: PR Checks (Lint, Typecheck, Build, Gate)
85 lines
3.2 KiB
JavaScript
85 lines
3.2 KiB
JavaScript
import assert from "node:assert/strict";
|
|
import { describe, it } from "node:test";
|
|
import {
|
|
PI_RUNTIME_PACKAGES,
|
|
scanTrackedManifests,
|
|
validateManifestSet,
|
|
validateWorkspaceOverrides,
|
|
} from "../check-pi-versions-pinned.mjs";
|
|
|
|
/*
|
|
FNXC:DesktopPackaging 2026-07-26-22:55:
|
|
Fixture versions track the workspace's exact matched Pi runtime pin (currently 0.82.1).
|
|
Keep these in sync when advancing overrides/manifests so the policy guard still exercises
|
|
matched-set and range rejection against the live pin surface.
|
|
*/
|
|
const PINNED_VERSION = "0.82.1";
|
|
const OTHER_VERSION = "0.82.0";
|
|
|
|
const pinnedManifest = {
|
|
dependencies: {
|
|
"@earendil-works/pi-ai": PINNED_VERSION,
|
|
"@earendil-works/pi-coding-agent": PINNED_VERSION,
|
|
},
|
|
};
|
|
|
|
function validate(manifest) {
|
|
return validateManifestSet([{ filePath: "packages/cli/package.json", manifest }]);
|
|
}
|
|
|
|
describe("check-pi-versions-pinned", () => {
|
|
it("passes against every guarded repository manifest", () => {
|
|
assert.deepEqual(scanTrackedManifests(), []);
|
|
});
|
|
|
|
it("rejects caret, tilde, wildcard, x, and comparator ranges", () => {
|
|
for (const version of [`^${PINNED_VERSION}`, `~${PINNED_VERSION}`, "*", "0.82.x", `>=${PINNED_VERSION}`]) {
|
|
const violations = validate({
|
|
...pinnedManifest,
|
|
dependencies: { ...pinnedManifest.dependencies, "@earendil-works/pi-ai": version },
|
|
});
|
|
assert.equal(violations.length > 0, true, `${version} must be rejected`);
|
|
}
|
|
});
|
|
|
|
it("rejects a matched-set version mismatch", () => {
|
|
const violations = validate({
|
|
...pinnedManifest,
|
|
dependencies: { ...pinnedManifest.dependencies, "@earendil-works/pi-coding-agent": OTHER_VERSION },
|
|
});
|
|
assert.equal(violations.some((violation) => violation.includes("same exact version")), true);
|
|
});
|
|
|
|
it("accepts a clean exact matched pair", () => {
|
|
assert.deepEqual(validate(pinnedManifest), []);
|
|
});
|
|
|
|
/*
|
|
FNXC:DesktopPackaging 2026-07-25-17:15:
|
|
Legacy desktop deploy resolves transitive pi-mono ranges without the workspace
|
|
lockfile. Guard every Pi runtime package in the staged closure, not only the
|
|
direct pi-ai and pi-coding-agent declarations, so a newly published patch
|
|
cannot split agent-core or tui from the exact runtime version.
|
|
*/
|
|
it("requires one exact workspace override for every staged Pi runtime package", () => {
|
|
const coherentOverrides = Object.fromEntries(PI_RUNTIME_PACKAGES.map((packageName) => [packageName, PINNED_VERSION]));
|
|
|
|
assert.deepEqual(validateWorkspaceOverrides(coherentOverrides), []);
|
|
assert.equal(
|
|
validateWorkspaceOverrides({ ...coherentOverrides, "@earendil-works/pi-tui": undefined })
|
|
.some((violation) => violation.includes("pi-tui") && violation.includes("must be pinned")),
|
|
true,
|
|
);
|
|
assert.equal(
|
|
validateWorkspaceOverrides({ ...coherentOverrides, "@earendil-works/pi-agent-core": `^${PINNED_VERSION}` })
|
|
.some((violation) => violation.includes("pi-agent-core") && violation.includes("exact semver")),
|
|
true,
|
|
);
|
|
assert.equal(
|
|
validateWorkspaceOverrides({ ...coherentOverrides, "@earendil-works/pi-tui": OTHER_VERSION })
|
|
.some((violation) => violation.includes("one exact version")),
|
|
true,
|
|
);
|
|
});
|
|
});
|