Skip to content

PAN-4541 - #4542

Merged
overdeck-agent[bot] merged 23 commits into
mainfrom
feature/pan-4541
Oct 4, 2026
Merged

overdeck-agent[bot] merged 23 commits into
mainfrom
feature/pan-4541

Conversation

@eltmon

@eltmon eltmon commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Issue: #4541

Acceptance Criteria

  • Reword the PAN-4508 JSDoc in settings-validation.ts so it has no from-quote text
  • Replace the regex in unresolvedBundleImports with inlined es-module-lexer
  • Document that the boot preflight resolves real import specifiers only

overdeck-agent[bot] and others added 23 commits October 4, 2026 04:41
Plan-Finalized: 575c90ab23823ee5dc23d78deb47bedc57f3d0399ead604ec15482e54d76d7f2
The PAN-4508 JSDoc comment on JEV_ZEN_BASE_URL contained the text
from "custom", which rolldown preserves into dist/dashboard/server.js.
The boot preflight's unresolvedBundleImports regex scanner matches
that text as an unresolvable bare import, so dashboardServerBootFailure
aborts every pan reload. Reword the comment so it no longer contains
import-shaped from-quote text.

Item: reword-jev-comment

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…eal lexer

unresolvedBundleImports (src/lib/bundle-imports.ts) used a regex that
matched the words from/import next to a quoted string anywhere in the
bundle text, including inside comments and string literals. A JSDoc
example in a bundled comment was indistinguishable from a real import,
so a single wrong-looking comment could block every pan reload.

Replace the regex with es-module-lexer, which tokenizes the bundle so
only genuine static imports, export-from re-exports, and dynamic
imports with a literal specifier are read; a package name mentioned in
a comment, string, template literal, or regex literal never counts.

es-module-lexer is a devDependency only (never a runtime dependency of
a consumer install) and is inlined into both the root CLI bundle and
the dashboard server bundle via deps.alwaysBundle, so the boot
preflight that detects an incomplete node_modules never itself needs
node_modules to run.

Verified: npm run build + lint:dist-externals show the lexer is
inlined everywhere (no bare es-module-lexer import in dist); the
old pre-fix regex scanner also passes the new dist/dashboard/server.js
(the installed CLI still runs it on the next reload); and a standalone
tsdown bundle of bundle-imports.ts (lexer inlined via the embedded
WASM) resolves the same dist/dashboard/server.js to [].

Item: lexer-scanner

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Add a "Boot preflight before switchover" subsection to
docs/MERGE-WORKFLOW.md (end of "Deploy progress on the project row")
covering what supervisorDeploymentFailure/dashboardServerBootFailure
check, that the check now tokenizes with es-module-lexer so only real
import/export specifiers count, that a refused reload leaves the old
dashboard running, and that the reload deploying a change runs the
already-installed CLI. Add one sentence to docs/BUILD.md's PAN-3209
externals section naming bundle-imports.ts and es-module-lexer's
devDependency/alwaysBundle status.

Also includes .overdeck/context/codebase/concerns.md, a pre-existing
uncommitted change from this issue's planning/discovery session
describing the same PAN-4541 landmine — carried along since it
documents this exact fix and the tree must be clean for `pan done`.

Item: docs-boot-preflight

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Lifecycle status fields only (status, sequence, updated), written by
pan task as items were claimed/completed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
All acceptance criteria below were verified during the item commits
that implemented them (894941c for lexer-scanner, 976e8e7 for
reword-jev-comment, d821e6c for docs-boot-preflight) and in this
session's verification run: npx vitest run tests/unit/lib/bundle-imports.test.ts
tests/unit/lib/deploy/dashboard-bundle-integrity.test.ts and
src/lib/channels/__tests__/pty-supervisor-locate.test.ts all passed;
npm run build + npm run lint:dist-externals showed es-module-lexer
inlined and not a bare dist import; the tsx one-liner and the
old-regex scan one-liner both printed [] against the freshly built
dist/dashboard/server.js; the standalone tsdown-bundled lexer probe
also printed []; and docs/MERGE-WORKFLOW.md and docs/BUILD.md were
grepped for the required headings and references.

Item: reword-jev-comment.ac1
Item: reword-jev-comment.ac2
Item: lexer-scanner.ac1
Item: lexer-scanner.ac2
Item: lexer-scanner.ac3
Item: lexer-scanner.ac4
Item: lexer-scanner.ac5
Item: lexer-scanner.ac6
Item: docs-boot-preflight.ac1
Item: docs-boot-preflight.ac2
Item: docs-boot-preflight.ac3

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 22 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: eltmon/overdeck/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 341dbd50-95af-4c29-aac8-c380288f7784
📥 Commits

Reviewing files that changed from the base of the PR and between 6daef11 and 7a874f8.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock, !bun.lock
📒 Files selected for processing (13)
  • .overdeck/context/codebase/concerns.md
  • .pan/continues/PAN-4541.xbrief.json
  • .pan/drafts/PAN-4541-critique.md
  • .pan/drafts/PAN-4541.md
  • .pan/specs/2026-10-04-PAN-4541-every-pan-reload-since-pan-4508-refuses-to-deploy-the-boot-preflight-s-import-scanner-reads-from-custom-inside-a-comment.xbrief.json
  • docs/BUILD.md
  • docs/MERGE-WORKFLOW.md
  • package.json
  • src/dashboard/server/tsdown.config.ts
  • src/lib/bundle-imports.ts
  • src/lib/jev/settings-validation.ts
  • tests/unit/lib/bundle-imports.test.ts
  • tsdown.config.ts
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@overdeck-agent overdeck-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

review verdict: passed

Lexer-based scanner verified: parity with old regex on real bundles, lexer inlined, CI green; one docs wording advisory

@overdeck-agent
overdeck-agent Bot merged commit cd27acf into main Oct 4, 2026
19 checks passed
@eltmon
eltmon deleted the feature/pan-4541 branch October 4, 2026 11:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant