fix(release): route core to extended-stable

Adapt the closed publish-plan and tarball identity checks from upstream c7810fc697 for the v6.11 publisher.
This commit is contained in:
Dallin Romney
2026-07-14 08:53:27 -07:00
parent e5dfc7d874
commit 6bcd4e0efe
2 changed files with 185 additions and 21 deletions
+150 -4
View File
@@ -1,6 +1,6 @@
// OpenClaw NPM Publish tests cover publish wrapper argument safety.
import { spawnSync } from "node:child_process";
import { mkdtempSync, rmSync, writeFileSync } from "node:fs";
import { execFileSync, spawnSync } from "node:child_process";
import { copyFileSync, mkdirSync, mkdtempSync, readFileSync, rmSync, writeFileSync } from "node:fs";
import { tmpdir } from "node:os";
import path from "node:path";
import { afterEach, describe, expect, it } from "vitest";
@@ -14,13 +14,49 @@ function makeTempDir(prefix: string): string {
return dir;
}
function runPublishWrapper(args: string[]) {
function runPublishWrapper(
args: string[],
env: NodeJS.ProcessEnv = {},
cwd: string = process.cwd(),
) {
return spawnSync("bash", [scriptPath, ...args], {
cwd: process.cwd(),
cwd,
encoding: "utf8",
env: { ...process.env, ...env },
});
}
function makeReleaseCheckout(root: string, version: string): string {
const checkout = path.join(root, "checkout");
const scriptsDir = path.join(checkout, "scripts");
mkdirSync(scriptsDir, { recursive: true });
writeFileSync(path.join(checkout, "package.json"), JSON.stringify({ version }), "utf8");
copyFileSync(scriptPath, path.join(checkout, scriptPath));
copyFileSync(
"scripts/openclaw-npm-extended-stable-release.mjs",
path.join(checkout, "scripts/openclaw-npm-extended-stable-release.mjs"),
);
mkdirSync(path.join(scriptsDir, "lib"));
copyFileSync(
"scripts/lib/npm-publish-plan.mjs",
path.join(checkout, "scripts/lib/npm-publish-plan.mjs"),
);
return checkout;
}
function makePackageTarball(root: string, packageJson?: string): string {
const packageDir = path.join(root, "package");
const tarball = path.join(root, "openclaw.tgz");
mkdirSync(packageDir);
if (packageJson === undefined) {
writeFileSync(path.join(packageDir, "README.md"), "missing package metadata", "utf8");
} else {
writeFileSync(path.join(packageDir, "package.json"), packageJson, "utf8");
}
execFileSync("tar", ["-czf", tarball, "-C", root, "package"]);
return tarball;
}
afterEach(() => {
for (const dir of tempDirs.splice(0)) {
rmSync(dir, { force: true, recursive: true });
@@ -67,4 +103,114 @@ describe("openclaw npm publish wrapper", () => {
expect(result.stdout).toBe("");
expect(result.stderr.trim()).toBe("error: unexpected npm publish argument: extra");
});
it.each(["beta", "latest"])("publishes the prepared tarball to the %s dist-tag", (distTag) => {
const tempRoot = makeTempDir("openclaw-npm-publish-");
const binDir = path.join(tempRoot, "bin");
const packageVersion = distTag === "beta" ? "2026.5.32-beta.1" : "2026.5.32";
const checkout = makeReleaseCheckout(tempRoot, packageVersion);
const tarball = makePackageTarball(tempRoot, JSON.stringify({ version: packageVersion }));
const npmLog = path.join(tempRoot, "npm.log");
mkdirSync(binDir);
writeFileSync(path.join(binDir, "npm"), `#!/bin/sh\nprintf '%s\\n' "$*" > "${npmLog}"\n`, {
mode: 0o755,
});
const result = runPublishWrapper(
["--publish", tarball],
{
OPENCLAW_NPM_PUBLISH_TAG: distTag,
PATH: `${binDir}:${process.env.PATH}`,
},
checkout,
);
expect(result.status).toBe(0);
expect(readFileSync(npmLog, "utf8")).toContain(
`publish ${tarball} --access public --tag ${distTag} --provenance`,
);
expect(result.stdout).toContain(`Resolved publish tag: ${distTag}`);
});
it("rejects a tarball whose package version differs from the checkout", () => {
const tempRoot = makeTempDir("openclaw-npm-publish-");
const packageVersion = JSON.parse(readFileSync("package.json", "utf8")).version as string;
const tarballVersion = `${packageVersion}-mismatch`;
const tarball = makePackageTarball(tempRoot, JSON.stringify({ version: tarballVersion }));
const result = runPublishWrapper(["--publish", tarball], {
OPENCLAW_NPM_PUBLISH_TAG: "extended-stable",
});
expect(result.status).toBe(2);
expect(result.stderr).toContain(
`npm publish tarball version mismatch: expected ${packageVersion}, got ${tarballVersion}`,
);
});
it.each([
["missing package.json", undefined, "missing a readable package/package.json"],
["malformed package.json", "{not-json", "package/package.json is malformed"],
["missing version", JSON.stringify({ name: "openclaw" }), "has no valid version"],
])("rejects a tarball with %s", (_label, packageJson, expectedError) => {
const tempRoot = makeTempDir("openclaw-npm-publish-");
const tarball = makePackageTarball(tempRoot, packageJson);
const result = runPublishWrapper(["--publish", tarball], {
OPENCLAW_NPM_PUBLISH_TAG: "extended-stable",
});
expect(result.status).toBe(2);
expect(result.stderr).toContain(expectedError);
});
it("rejects a pre-.33 final version on extended-stable", () => {
const tempRoot = makeTempDir("openclaw-npm-publish-");
const checkout = makeReleaseCheckout(tempRoot, "2026.5.32");
const result = runPublishWrapper(
["--publish"],
{ OPENCLAW_NPM_PUBLISH_TAG: "extended-stable" },
checkout,
);
expect(result.status).not.toBe(0);
expect(result.stderr).toContain(
"Extended-stable npm publication requires release patch 33 or above",
);
});
it("routes the prepared 2026.6.33 tarball only to extended-stable", () => {
const tempRoot = makeTempDir("openclaw-npm-publish-");
const binDir = path.join(tempRoot, "bin");
const checkout = makeReleaseCheckout(tempRoot, "2026.6.33");
const tarball = makePackageTarball(tempRoot, JSON.stringify({ version: "2026.6.33" }));
const npmLog = path.join(tempRoot, "npm.log");
mkdirSync(binDir);
writeFileSync(path.join(binDir, "npm"), `#!/bin/sh\nprintf '%s\\n' "$*" > "${npmLog}"\n`, {
mode: 0o755,
});
const result = runPublishWrapper(
["--publish", tarball],
{
OPENCLAW_NPM_PUBLISH_TAG: "extended-stable",
PATH: `${binDir}:${process.env.PATH}`,
},
checkout,
);
expect(result.status).toBe(0);
expect(readFileSync(npmLog, "utf8")).toContain(
`publish ${tarball} --access public --tag extended-stable --provenance`,
);
expect(result.stdout).toContain("Resolved publish tag: extended-stable");
expect(result.stdout).not.toContain("Resolved publish tag: beta");
});
it("rejects unknown requested dist-tags instead of falling back to beta", () => {
const result = runPublishWrapper(["--publish"], {
OPENCLAW_NPM_PUBLISH_TAG: "nightly",
});
expect(result.status).not.toBe(0);
expect(result.stderr).toContain('Unsupported npm dist-tag "nightly"');
});
});