fix(sdk): enforce a coherent Fresh/SDK cache-provider closure - #1595
Conversation
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TKxrWGp5uxEHQ2NyZiZSMF
|
[PHASE: RESEARCH] The consumer failure is a resolvable-identity split that existing producer-side specifier checks do not reach. Findings
Unverified boundaryPer-referrer import-map scopes and direct literal versioned JSR imports are not fully covered by one generated app-level resolver probe. Generated NetScript workspaces emit neither; PLAN-EVAL must rescope before implementation if #1589 is intended to cover arbitrary hand-authored graphs. Artifact
|
|
[PHASE: PLAN] Option 1 is locked: reject an incoherent Fresh/SDK cache-provider closure at init and before generated Fresh dev/build tasks start. Locked design
Slices
GatePLAN-EVAL is pending and is a hard stop. Implementation has not begun; this PR remains draft at Artifacts
|
|
@openhands-agent model=openrouter/minimax/minimax-m3 output=pr-comment iterations=500 phase=plan head=ec596b3532b91ccebe82c46971767e3bf81f8763 Trusted base SHA: eb373db use harness SKILL
Act as the formal PLAN-EVAL session for this pull request. Do not edit files, create commits, push, Return concise findings with exact evidence and required amendments. End with exactly one supported |
OpenHands Agent — Did not runOPENHANDS_VERDICT: NONE Model: OpenHands Agent SummaryThe agent step did not run (outcome: cancelled). This is a workflow failure, not a task verdict. Diagnostics
See the uploaded Actions artifact for bootstrap.log and agent.log when present. Run: https://github.com/rickylabs/netscript/actions/runs/31616569894 |
|
[PHASE: FALLBACK PLAN-EVAL] [VERDICT: PASS] The automatic MiniMax PLAN-EVAL (run Verdict: PASS. Option 1 is correctly scoped for the reported configuration; the residual gaps are closure-membership and graph-truth limitations to be written into the plan, not a redesign. Verified (selected)
FindingsC1 — C2 — the check compares import-map identities, never the actual Fresh→SDK graph edge (advisory). "Fresh version == SDK version" is a proxy for "Fresh loads the app's SDK instance". Since Fresh does not declare its cache-path SDK dependency at all, the real constraint is whatever JSR recorded at publish, and the proxy holds only under lockstep publishing. Realistic trigger: prereleases do not satisfy C3 — binding the verifier to a member config may itself false-positive (advisory, would become blocking). The generated manifest contains C4 — non-exact consumer specifiers have no stated policy (advisory). A consumer-edited C5 — no escape hatch or warn mode (advisory). A deliberate transitional split becomes a hard non-zero on C6 — coverage stops at build-from-source (advisory). Sufficiency and false positivesOption 1 is sufficient for every NetScript-generated workspace, which uses bare aliases only. It leaves open, in decreasing realism: a Fresh→SDK constraint diverging from version-equality under non-lockstep publishing (C2); hand-authored literal specifiers and per-referrer The two genuine false-positive risks are mechanical, not policy: C3 and C4. NextPlan amendments C1, C2, C4 recorded before S1 fixtures freeze; S1 runs the C3 probe against a real generated workspace first and treats a task-shape change as drift. Implementation proceeds after that. |
A1 excludes @netscript/fresh-ui from the closure with the evidence that its pinned SDK subpaths carry no cache/query imports, so it cannot produce a second provider instance -- stated because the parity test freezes the list. A2 records that version-equality is a proxy for the Fresh->SDK graph edge and holds only under lockstep publishing, since Fresh does not map @netscript/sdk cache paths at all. A3 makes non-exact specifiers fail closed. A4 makes the generated-workspace catalog: probe an S1 prerequisite. The isPartial prohibition is restated intact. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TKxrWGp5uxEHQ2NyZiZSMF
|
[PHASE: IMPL] Implemented the amended PLAN-EVAL design at:
The PR remains draft. No local evaluator, OpenHands trigger, ready transition, merge, E2E, or canary action was performed. Automatic label-driven IMPL-EVAL remains with the orchestrator. A4 prerequisite — verbatimA4 passes: member-config isolation does not break Enforcement and exact operator diagnosticEnforcement fires during app-manifest initialization and from generated app A coherent stable workspace prints: Negative/coherent focused evidence — verbatimRequired scoped gates — verbatimThe full verbatim The mandated package task was also run exactly as requested. Its final verdict and three failures were: Those three cwd-sensitive checks pre-existed and point outside the owned/modified paths. They remain explicitly open in the PR Definition of Done; they were not papered over. False-positive boundary / published surfaceThe verifier evaluates one generated app at a time, so separate app configs may legitimately select different internally coherent exact releases; there is no workspace-global version aggregation. Within one app, mixed Fresh/SDK releases are rejected because they can split the cache-provider instance. Hand-authored literal JSR imports and arbitrary per-referrer scoped maps remain unverified/out of scope. Exact version equality remains the A2 lockstep-publishing proxy. No published Fresh/SDK/telemetry surface changed. No provider ownership or partial-navigation cache behavior changed. No dependency was added and |
|
[PHASE: IMPL] gate appendix Full verbatim output for the required quality gate referenced by the implementation summary: |
|
[PHASE: IMPL] resync + slice review Resynced onto current Merge, not rebase — Re-verified on the merged head, because
On those 3 failures. They are The Definition-of-Done box that previously read Acknowledging the A4 result, since it was the binding prerequisite the amended plan added: the Flipping to ready now, which fires the automatic IMPL-EVAL once at this exact head. No local evaluator, no manual OpenHands. |
|
@openhands-agent model=openrouter/deepseek/deepseek-v4-flash-0731 output=pr-comment iterations=800 phase=impl head=cbf6d5c27d4759dd8d7d7a215fef6bd8f54383d0 Trusted base SHA: f542f31 use harness SKILL
Act as the formal IMPL-EVAL session for this pull request. Do not edit files, create commits, push, Return concise, severity-ranked findings with exact evidence and required action. End with exactly |
OpenHands Agent — CompletedOPENHANDS_VERDICT: PASS Model: OPENHANDS_VERDICT: PASS IMPL-EVAL — PR #1595 fix(sdk): enforce a coherent Fresh/SDK cache-provider closureEvaluator session for #1589 / PR #1595. Trusted base VerdictPASS — the approved first-cut plan (option 1, consumer-boundary closure rejection) is Changes (verified at head cbf6d5c)
Validation (run independently at head)
Plan / Process compliance
Response to review / issue commentsNo unresolved review threads ( Remaining risks (documented, not blocking)
Run: https://github.com/rickylabs/netscript/actions/runs/31622416983 |
|
OPENHANDS_VERDICT: PASS Formal IMPL-EVAL for PR #1595 (issue #1589), trusted base Outcome: PASS. The approved first-cut plan (option 1, consumer-boundary Fresh/SDK closure Evidence (independently verified at head)
Non-blocking notes
Close-gate: #1589's five acceptance boxes each have linked evidence (verified), |
|
@openhands-agent model=openrouter/deepseek/deepseek-v4-flash-0731 output=pr-comment iterations=800 phase=impl head=cbf6d5c27d4759dd8d7d7a215fef6bd8f54383d0 Trusted base SHA: 6619603 use harness SKILL
Act as the formal IMPL-EVAL session for this pull request. Do not edit files, create commits, push, Return concise, severity-ranked findings with exact evidence and required action. End with exactly |
OpenHands Agent — Did not runOPENHANDS_VERDICT: NONE Model: OpenHands Agent SummaryThe agent step did not run (outcome: cancelled). This is a workflow failure, not a task verdict. Diagnostics
See the uploaded Actions artifact for bootstrap.log and agent.log when present. Run: https://github.com/rickylabs/netscript/actions/runs/31623520897 |
…the PR head D-11. Measured across four PRs: label-triggered dispatches report headSha equal to the branch head, draft-to-ready dispatches report the base/merge ref. #1595 reached ready-merge on a PASS whose run metadata pointed at old main, and #1602's evaluator was running against main itself. Standing rule: flip to ready and apply the status label as a separate action, assert run.headSha == pr.headRefOid before consuming any verdict, and treat any post-ready change as voiding the prior verdict. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TKxrWGp5uxEHQ2NyZiZSMF
Summary
Implements the P0 first cut for #1589: generated NetScript apps reject an incoherent Fresh/SDK cache-provider closure during init and before Fresh dev/build reaches Vite. The verifier names every resolved closure member and every involved version instead of allowing partial navigation to reach
[NetScript SDK] Cache provider not initialized.Chosen option: consumer-boundary closure rejection. It preserves the current module-local provider ownership and the verified coherent full-canary workaround. Exact peer metadata was rejected as the first cut because Fresh already pins its internal SDK exactly while Deno can still load a separately pinned consumer copy. A
globalThisprovider was rejected because it changes ownership and forces a cross-version ABI choice. Version equality remains a lockstep-publishing proxy for the real Fresh→SDK graph edge.Scope
deps:closure,dev, andbuildtasks before Vite@netscript/fresh-uiis excluded: its pinned SDKdesktopandauto-updatesubpaths contain no cache/query/Fresh imports and cannot create the second cache-provider instanceSlices
ec596b353,ff2c181497f8bc1c405807bba7dValidation
catalog:probe: normal upward discovery and explicit member config both resolved rootzod@4.4.3, exit 0ok | 43 passed (17 steps) | 0 failed (2s)run-deno-check.ts: exit 0, 865 files, 8/8 batches, 0 findingsrun-deno-lint.ts: exit 0, 865 files, 5 batches, 0 findingsrun-deno-fmt.ts: exit 0, 865 files, 5/5 batches, 0 findingsdeno task quality:gate: exit 0; quality scanok:true, no findings, doctrine FAIL=0deno task --cwd packages/cli test:FAILED | 801 passed (533 steps) | 3 failed (2m14s); all three are pre-existing cwd-sensitiveNotFoundchecks fordocs/site/durable-workflows/streams.md,packages/cli/e2e/src/application/gates/scaffold/service-env/configure-service-env.ts, anddocs/site/quickstart.vtoe2e:cliwas not run, per the implementation-slice prohibitiondeno.lockunchangedHarness
.llm/runs/release-0.0.6-features--orchestration/slices/plan-1589.mdDrift / Debt
.netscriptverifier cannot see app imports. The root task delegates withdeno task --cwd apps/<app>.deno.lockunchanged.Definition of Done
quality:gatepasscbf6d5c27:809 passed (533 steps) | 3 failed. The 3 failures resolve repo-root-relative paths and fail under--cwd packages/cliindependently of this branch (service-env-gates_test.ts:96,quickstart-command-drift_test.ts:4, and thedocs/site/durable-workflows/streams.mdreader). This diff touches onlypackages/cli/src/kernel/**— zero files underdocs/site/**orpackages/cli/e2e/**. Tracked as test(cli): the prescribed deno task --cwd packages/cli test is always red — 3 tests resolve repo-root-relative paths #1604.cbf6d5c27, independently re-running the consumer preflight subprocess against temp fixtures; no blocking findings.