build: In the obsidian-connor repo, make the build reproducible and verifiable from a clean checkout: ensure package.… #17

Merged
Connor merged 1 commit from build/c4e46db8 into main 2026-09-14 14:05:08 +00:00
Owner

What changed

build/c4e46db8 → main — 7 file(s), +211/−6.

  • .forgejo/workflows/gate.yml
  • README.md
  • buildstamp.mjs
  • esbuild.config.mjs
  • package-lock.json
  • package.json
  • verify-build.mjs

Why

Done. Gate is green with the new check inside it.

What I changed

The ask was four things, and three of them were already true in obsidian-connor — worth knowing before you read the diff:

  • Single npm run build → main.js at the repo root: already there (tsc -noEmit -skipLibCheck && node esbuild.config.mjs production), with manifest.json and styles.css committed beside it.
  • Toolchain pinned with a committed lockfile: package-lock.json is tracked, lockfileVersion 3, and CI already used npm ci. One entry was genuinely unpinned — "obsidian": "latest" — so I pinned it to ^1.13.1 (the version the lock already resolved) and fixed the lockfile's stale root version (0.1.0 → 0.4.0). The gate's own npm ci re-installed cleanly from the edited lock, which is the proof those two files are still in sync.
  • main.js stays gitignored: untouched, and now enforced — see below.
  • The verification check: genuinely missing. That's the real work.

New verify-build.mjs (root, matching esbuild.config.mjs/esbuild.test.mjs placement) is now the gate's build step — gate runs check && verify:build && test, so it is the build with assertions after it, nothing is built twice. It refuses to run if main.js is tracked by git, deletes any existing main.js, runs the real npm run build as a subprocess, then asserts all three artefacts exist and are non-empty and that the versions agree. It does no npm ci of its own — the install is the caller's job, so nothing in the test path reaches the network. […]

Gate

npm run gate ran 196 tests in 2.6s and exited 0 — green.

Built by Connor's backend backburner (dispatch c4e46db8) in an isolated clone; shipped deterministically by ship.py. The full build notes were spoken in conversation and stored in memory (agent-dispatch:c4e46db8). Review is the gate.


The brief this build was given

Kept for provenance. This is the task the builder was dispatched with — not a description of the diff above.

In the obsidian-connor repo, make the build reproducible and verifiable from a clean checkout: ensure package.json has a single npm run build script that produces main.js (plus manifest.json and styles.css) into the repo root or a dist/ directory, pin the build toolchain in devDependencies with a committed lockfile, and add a test or CI check that runs the build from a clean tree and asserts the artifact exists and is non-empty and that its reported version matches manifest.json. Do not un-gitignore main.js. Ship this as a pull request.

This task is one step of my plan: working-list item #79: Nothing builds the plugin artifact — Connor's /vault/plugin serves the mapped obsidian-connor checkout's files as they stand and deliberately never runs npm, so with main.js gitignored and the canonical checkout unbuilt the endpoint 503s "unbuilt" and self-update can never offer anything. Build the

Result of earlier step 1 (read in obsidian-connor: Read the /vault/plugin endpoint implementation in the connor service and the obs):
I read both repos, the live publish state and the journal. Findings below — and one thing I could not do.

I could not write the notes file

This run is read-only: I have no Write tool, so /home/joel/.local/state/connor/notes/plugin-build-analysis.md does not exist. /home/joel/.local/state/connor/notes/ has no files in it at all (Glob returned nothing). The full note text is below, ready to be dropped in verbatim by a step that can write.

The headline: item #79 is already done, and the build ran three times today

The premise in the working-list item — "nothing builds the plugin artifact… every request 503s unbuilt" — was true when it was written and is no longer true on this host. Two independent layers agree:

  • /home/joel/.local/state/connor/plugin-publish/published.json names v0.4.0, commit 6436a306…, published 2026-09-14T12:29:35+00:00, digest f15eb27340a0c678…, with all three files (main.js 122927 B).
  • journal, unit service: 2026-09-14T07:29:35-05:00 … connor: plugin publish [merge:ZSDev/obsidian-connor#16]: ok — v0.4.0 from 6436a306, /vault/plugin serves it, preceded by the same for #14 and #15, and at 08:27:22 `plugin publish: v0.4.0 is already p
### What changed `build/c4e46db8` → `main` — 7 file(s), +211/−6. - `.forgejo/workflows/gate.yml` - `README.md` - `buildstamp.mjs` - `esbuild.config.mjs` - `package-lock.json` - `package.json` - `verify-build.mjs` ### Why Done. Gate is green with the new check inside it. ## What I changed The ask was four things, and three of them were already true in obsidian-connor — worth knowing before you read the diff: - **Single `npm run build` → main.js at the repo root**: already there (`tsc -noEmit -skipLibCheck && node esbuild.config.mjs production`), with `manifest.json` and `styles.css` committed beside it. - **Toolchain pinned with a committed lockfile**: `package-lock.json` is tracked, lockfileVersion 3, and CI already used `npm ci`. One entry was genuinely unpinned — `"obsidian": "latest"` — so I pinned it to `^1.13.1` (the version the lock already resolved) and fixed the lockfile's stale root `version` (`0.1.0` → `0.4.0`). The gate's own `npm ci` re-installed cleanly from the edited lock, which is the proof those two files are still in sync. - **`main.js` stays gitignored**: untouched, and now *enforced* — see below. - **The verification check**: genuinely missing. That's the real work. New `verify-build.mjs` (root, matching `esbuild.config.mjs`/`esbuild.test.mjs` placement) is now the gate's build step — `gate` runs `check && verify:build && test`, so it *is* the build with assertions after it, nothing is built twice. It refuses to run if `main.js` is tracked by git, deletes any existing `main.js`, runs the real `npm run build` as a subprocess, then asserts all three artefacts exist and are non-empty and that the versions agree. It does no `npm ci` of its own — the install is the caller's job, so nothing in the test path reaches the network. […] ### Gate `npm run gate` ran 196 tests in 2.6s and exited 0 — green. Built by Connor's backend backburner (dispatch `c4e46db8`) in an isolated clone; shipped deterministically by `ship.py`. The full build notes were spoken in conversation and stored in memory (`agent-dispatch:c4e46db8`). Review is the gate. --- ### The brief this build was given _Kept for provenance. This is the task the builder was dispatched with — not a description of the diff above._ > In the obsidian-connor repo, make the build reproducible and verifiable from a clean checkout: ensure package.json has a single `npm run build` script that produces main.js (plus manifest.json and styles.css) into the repo root or a dist/ directory, pin the build toolchain in devDependencies with a committed lockfile, and add a test or CI check that runs the build from a clean tree and asserts the artifact exists and is non-empty and that its reported version matches manifest.json. Do not un-gitignore main.js. Ship this as a pull request. > > This task is one step of my plan: working-list item #79: Nothing builds the plugin artifact — Connor's /vault/plugin serves the mapped obsidian-connor checkout's files as they stand and deliberately never runs npm, so with main.js gitignored and the canonical checkout unbuilt the endpoint 503s "unbuilt" and self-update can never offer anything. Build the > > Result of earlier step 1 (read in obsidian-connor: Read the /vault/plugin endpoint implementation in the connor service and the obs): > I read both repos, the live publish state and the journal. Findings below — and one thing I could not do. > > ## I could not write the notes file > > This run is read-only: I have no Write tool, so `/home/joel/.local/state/connor/notes/plugin-build-analysis.md` does not exist. `/home/joel/.local/state/connor/notes/` has no files in it at all (Glob returned nothing). The full note text is below, ready to be dropped in verbatim by a step that can write. > > ## The headline: item #79 is already done, and the build ran three times today > > The premise in the working-list item — "nothing builds the plugin artifact… every request 503s unbuilt" — was true when it was written and is **no longer true on this host**. Two independent layers agree: > > - `/home/joel/.local/state/connor/plugin-publish/published.json` names v0.4.0, commit `6436a306…`, published `2026-09-14T12:29:35+00:00`, digest `f15eb27340a0c678…`, with all three files (main.js 122927 B). > - journal, unit `service`: `2026-09-14T07:29:35-05:00 … connor: plugin publish [merge:ZSDev/obsidian-connor#16]: ok — v0.4.0 from 6436a306, /vault/plugin serves it`, preceded by the same for #14 and #15, and at 08:27:22 `plugin publish: v0.4.0 is already p
build: In the obsidian-connor repo, make the build reproducible and verifiable…
All checks were successful
gate / gate (pull_request) Successful in 9s
cf2ff45c37
In the obsidian-connor repo, make the build reproducible and verifiable from a clean checkout: ensure package.json has a single `npm run build` script that produces main.js (plus manifest.json and styles.css) into the repo root or a dist/ directory, pin the build toolchain in devDependencies with a committed lockfile, and add a test or CI check that runs the build from a clean tree and asserts the artifact exists and is non-empty and that its reported version matches manifest.json. Do not un-gitignore main.js. Ship this as a pull request.

This task is one step of my plan: working-list item #79: Nothing builds the plugin artifact — Connor's /vault/plugin serves the mapped obsidian-connor checkout's files as they stand and deliberately never runs npm, so with main.js gitignored and the canonical checkout unbuilt the endpoint 503s "unbuilt" and self-update can never offer anything. Build the

Result of earlier step 1 (read in obsidian-connor: Read the /vault/plugin endpoint implementation in the connor service and the obs):
I read both repos, the live publish state and the journal. Findings below — and one thing I could not do.

## I could not write the notes file

This run is read-only: I have no Write tool, so `/home/joel/.local/state/connor/notes/plugin-build-analysis.md` does not exist. `/home/joel/.local/state/connor/notes/` has no files in it at all (Glob returned nothing). The full note text is below, ready to be dropped in verbatim by a step that can write.

## The headline: item #79 is already done, and the build ran three times today

The premise in the working-list item — "nothing builds the plugin artifact… every request 503s unbuilt" — was true when it was written and is **no longer true on this host**. Two independent layers agree:

- `/home/joel/.local/state/connor/plugin-publish/published.json` names v0.4.0, commit `6436a306…`, published `2026-09-14T12:29:35+00:00`, digest `f15eb27340a0c678…`, with all three files (main.js 122927 B).
- journal, unit `service`: `2026-09-14T07:29:35-05:00 … connor: plugin publish [merge:ZSDev/obsidian-connor#16]: ok — v0.4.0 from 6436a306, /vault/plugin serves it`, preceded by the same for #14 and #15, and at 08:27:22 `plugin publish: v0.4.0 is already p

Built by my backend backburner (dispatch c4e46db8), diff verified by git; shipped by ship.py. Nothing merges without review.
reviewer-bot left a comment

HELD FOR HUMAN INDEPENDENT REVIEW

reviewer-bot withholds auto-approval on this PR (trust-surface: touches trust surface ['.forgejo/workflows/gate.yml']). Per ADR-0007 D3 / ADR-0008 D4 the independence axis on high-tier / trust-surface changes must be closed by a human independent principal, not the local-model reviewer. Holding for human review — this bot will not post APPROVED here.

**HELD FOR HUMAN INDEPENDENT REVIEW** `reviewer-bot` withholds auto-approval on this PR (trust-surface: touches trust surface ['.forgejo/workflows/gate.yml']). Per ADR-0007 D3 / ADR-0008 D4 the independence axis on high-tier / trust-surface changes must be closed by a **human** independent principal, not the local-model reviewer. Holding for human review — this bot will not post APPROVED here.
Joel approved these changes 2026-09-14 14:04:51 +00:00
Connor merged commit ab28d7507e into main 2026-09-14 14:05:08 +00:00
Connor deleted branch build/c4e46db8 2026-09-14 14:05:09 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ZSDev/obsidian-connor!17
No description provided.