Repository navigation
chore(deps): update runtimes and supporting dependencies - #2803
Conversation
There was a problem hiding this comment.
Changes requested: The harness upgrades leave runtime pins inconsistent, and rendering dependency changes leave all screenshot artifacts stale.
Warning
Changes requested · head 2debd9a · 3 findings: 1 major, 2 minor
| Severity | Finding | Where |
|---|---|---|
| major | F1 Spec contradiction — harness.md item 12: OpenCode dependencies upgrade without the runtime pin | package.json:105 |
| minor | F2 Spec contradiction — harness-pi.md item 3: pi packages and execution images use different versions | package.json:93 |
| minor | F3 Spec contradiction — docs-site.md item 20: rendering dependencies change without screenshot regeneration | web/package.json:17 |
F1 invariant: OpenCode CLI, protocol/schema packages, adapter version checks and every execution image must use one supported exact version, so the installed CLI passes readiness and compatible sessions can reattach.
- A fresh local npm-run OpenCode request starts the installed @opencode/cli 2.0.18; launchOpenCode receives /api/info version 2.0.18. → The supported adapter version matches 2.0.18 and readiness proceeds without OpenCodeNotReadyError.
- A local OpenCode rebuild or relaunch starts the same installed 2.0.18 CLI. → The replacement server passes the same supported-version readiness check.
- The client contract is checked against installed @opencode/protocol and @opencode/schema 2.0.18. → Both packages match OPENCODE_VERSION, and the adapter's routes and consumed response shapes conform to that version.
- A preset without a workspace starts OpenCode from the root Dockerfile runtime stage, currently pinned and proven at 2.0.12. → The bot image installs and proves the same 2.0.18 version as the upgraded CLI, schema and adapter.
- A resident-backed run starts OpenCode from deploy/cloudflare-resident/Dockerfile, including the worker1 version proof, currently 2.0.12. → The global install and thread-user proof both match the upgraded adapter's exact 2.0.18 pin.
- A cold sandbox run starts OpenCode from deploy/cloudflare-sandbox/Dockerfile, currently installed and proven at 2.0.12. → The sandbox install and build-time proof match the same supported 2.0.18 pin.
- A same-container resume probes a live 2.0.18 OpenCode server in reattachOpenCode. → Version identity alone does not reject the supported server; remaining session, authentication and feed checks still apply.
F2 invariant: The bot's pi-ai library, development pi-coding-agent, published runtime dependency and all three image installs and proofs must move together at one exact pi version.
- Root package.json and packages/switchboard/package.json resolve @earendil-works/pi-ai 0.87.1. → The library pin equals the pi-coding-agent version used by every image.
- npm-run CLI requests and SDK/real-binary checks use the development @earendil-works/pi-coding-agent 0.87.1. → The development harness version equals the deployed harness version and the exact version guard.
- The root Dockerfile globally installs and proves pi 0.87.0 for bot-host runs. → Its install and version proof use 0.87.1 consistently with the upgraded package dependencies.
- deploy/cloudflare-sandbox/Dockerfile installs and proves pi 0.87.0 for cold workspace runs. → Its install and proof use the same upgraded 0.87.1 pin.
- deploy/cloudflare-resident/Dockerfile globally installs pi 0.87.0 and separately proves that version as worker1. → Both global and thread-user proofs use 0.87.1, with imagePiHarness.test.ts retaining exact cross-image/library equality.
F3 invariant: Every screenshot surface's committed manifest must hash its current rendering dependency closure, with its light and dark pictures regenerated through screenshots:gen when those inputs change.
- home-empty light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current package.json, web/package.json and projected package-lock.json hashes.
- home-conversation light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- home-live light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- runs-index light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- runs-index-viewing-as light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- run-page light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- residents light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- costs light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- plane light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- costs-users light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- metrics light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- costs-models light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- scheduled light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- unit-page light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- unit-page-coding-only light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- unit-search light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- unit-search-landed light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- conductor-page light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- review-page light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- settings-mcps light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- settings-channel light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
- settings-installation light/dark pictures and manifest after the dependency bump. → Regenerated artifacts match the current rendering dependency hashes.
Full review
F1 (high confidence): The installed OpenCode CLI is now 2.0.18, but OPENCODE_VERSION remains 2.0.12. A local OpenCode request therefore fails immediately at process.ts:711–712: “the opencode on PATH is 2.0.18; this build drives 2.0.12.” Reattachment rejects that version too, while all three images still ship the older binary. Move the adapter, image installs/proofs and spec to 2.0.18 together, preserving strict version checks and validating the upgraded protocol behavior.
F2 (high confidence): Both pi packages move to 0.87.1, but the bot, resident and sandbox images—and their exact-version guard—remain at 0.87.0. This violates the required library/CLI/image equality: local verification exercises a different pi version from deployed runs. Update every image install and version proof, including the resident’s worker1 proof, together with the guard.
F3 (high confidence): The rendering dependency changes invalidate all 22 screenshot surfaces, but no pictures or manifests are regenerated. Their dependency hashes match the merge-base and differ at this head; screenshots:check reports all surfaces stale. Run npm run screenshots:gen and commit the generated artifacts rather than editing hashes or weakening the freshness check.
2debd9a to
7dc37c8
Compare
Co-Authored-By: coreplane-switchboard[bot] <318072483+coreplane-switchboard[bot]@users.noreply.github.com>
7dc37c8 to
bf46f92
Compare
justinhelmer
left a comment
There was a problem hiding this comment.
Reviewed locally at exact head bf46f92.
F1 fixed: OpenCode CLI, protocol/schema packages, client readiness pin, and all image install/version proofs agree at 2.0.18. Complete protocol samples and real start/rebuild/reattach tests pass.
F2 fixed: Pi library/development CLI/published package pins and all image proofs agree at 0.87.1.
F3 fixed: All 22 surface manifests and 44 captures were regenerated after rebase. The final repeat retained all 44 PNGs byte-for-byte; freshness and output checks pass.
The additional CI failure is fixed by treating session.metadata.updated as opaque structural metadata. Exact event-catalogue equality, unknown-event guards, and the bridge's non-terminal behavior remain covered.
Validation: npm run verify (root and all workspaces) passed; 176 focused harness/image tests and 66 screenshot tests passed; required spec coverage passed. No actionable issue found in the final dependency/compatibility diff. Current-head remote CI must finish successfully before merge.
TL;DR
Updates the grouped runtime and development dependencies, keeping the installed Pi/OpenCode packages and all execution images on the same exact versions. Regenerated dashboard captures and complete protocol handling make the upgraded dependency set verifiable.
Why
The grouped update previously left image/client pins behind the installed packages and omitted a new OpenCode metadata event. Those mismatches failed readiness and CI; renderer dependency changes also invalidated screenshot records.
Where to look
Feedback wanted
Check the runtime/library/image agreement and metadata-event classification; the unknown-event and strict version guards must remain intact.
Risk
Dependency installs and runtime protocols change. Generated lockfile churn exceeds 400 lines; keeping manifests and images together avoids mixed versions. Roll back the dependency/image pins and regenerate captures together if needed.
Verified
Full npm run verify and all workspace checks pass; 176 focused harness tests pass, including the real OpenCode binary. Required current-head CI and local review pass.
Decisions and validation
Rebased onto a8d347d on the original Dependabot branch. Scratch logs remain outside the repository.