5 Commits
Author SHA1 Message Date
zhu1090093659 27e138d1f7 fix(release): bring the root alias version along with the release tag
The root package.json is private and unpublished, so the release bump never
moved its version: a git or link install of the repository kept reporting
0.1.1 in the plugin manager long after the family reached 0.4.x.

The root alias is part of the released contract, so pin its own version the
same way its aggregate dependency is pinned: verify-version now fails the
publish when the root version drifts from the tag, and the release bump
covers the root manifest beside the family packages.
2026-09-24 23:15:52 +08:00
zhu1090093659 b4944353a5 refactor(scripts): drop the packages/skins root the satellites took
The skin, pet and community packages left this repository, so packages/skins/
never exists in a checkout of it. Every scanner that still walked it as a
second root did so defensively — family-packages.mjs and
coverage-gate.discoverPackages listed it first and guarded the walk with
existsSync, aggregate.mjs looked for a second aggregate manifest and a second
package index under it, e2e-mount-rewrite searched it for workspace packages,
and seven test files built fixtures under it. The walkers now name packages/ as
the single root and the fixtures and comments follow; modules that only carried
the root in a doc comment are reworded.

scripts/coverage-baseline.json loses the three packages no longer measured here;
its sixteen keys now name exactly the sixteen package directories on disk.

The in-repo fallback paths in scripts/market-build stay untouched: they are the
documented route for building from a checkout that still carries the packages,
and the fixture-based market-build tests populate them deliberately.
2026-09-24 09:48:23 +08:00
zhu1090093659 058c981c75 fix(release): pin the root alias to the exact released aggregate
The root git bundle ships the aggregate's generated patch while resolving its
modules from the npm dependency; the ^0.3.6 range could resolve an aggregate
whose exports predate rows the patch mounts, and a lockfile kept that older
child when only the git ref moved, so every web-ui-* row failed to import
(#1442). The dependency now names the exact released version, and
verify-version.mjs fails the release when it drifts from the tag.
2026-09-10 18:16:18 +08:00
zhu1090093659 4ffe98fbe1 test(scripts): add the cohort rollout acceptance gate
scripts/rollout-verify.sh turns the post-upgrade checks into one
command: host dsh --version must satisfy the scaffold's dsh.engines.dsh
floor, every dsh-family reference in the root lockfile (importers
key/specifier/version triples, packages-section keys, snapshot
dependency rows, peer-suffix aware) must resolve at exactly the floor's
cohort version, the dsh-sdk-upgrade skill's profile cohort check runs
when present, and an unauthenticated request to DSH_WEB_PORT must
answer 401/403. The pure checks live in scripts/lib/rollout-verify.mjs
behind node:test contracts; the root-lockfile purity assertion pins the
current 0.1.5-alpha.2 cohort so the next cohort move updates them
together.

Executed rollout evidence and profile acceptance notes are recorded in
the cohort Agent Note (en/zh): managed service restarted on alpha.2,
web profile tracks the host via symlinks, trading-web stays owned by
the desktop app runtime, default profile exa gap refilled, real tool
call + pet stream phases + SessionRail + persistence verified in the
GUI.
2026-09-10 00:43:04 +08:00
zhu1090093659 a605ca1c4d refactor(scripts): share one family-package walker across four scripts
verify-version, release-assets, verify-docs, and link-profile each walked
packages/ + packages/skins/ with their own drifting copy. scripts/lib/
family-packages.mjs is now the single implementation; each script keeps a
thin wrapper with its own shape.
2026-08-17 13:12:39 +08:00