Skip to content

fix(release): preserve dependency identity across SDK stages - #253

Merged
f0rr0 merged 6 commits into
mainfrom
f0rr0/fix-wasix-addon-qualification
Oct 5, 2026
Merged

f0rr0 merged 6 commits into
mainfrom
f0rr0/fix-wasix-addon-qualification

Conversation

@f0rr0

@f0rr0 f0rr0 commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Independent product versions made source builds use newer workspace producers while package gates interpreted them as older, exactly pinned release carriers. For example, runtime 0.3.1 binaries were paired with SDK and extension metadata pinning 0.3.0, breaking WASIX host qualification and Android/iOS app assembly. This change keeps source qualification truthful while preserving immutable release dependency pins.

  • Derive compiled Rust source ownership from Cargo's local runtime, build and target dependencies, including inherited/renamed dependencies and custom source paths. Declare embedded generated payload producers separately. Binaries that embed changed code or payloads become release consumers; dynamically loaded runtimes and source facades retain independent release boundaries. Moon tracks those source inputs and declares Cargo only where needed.
  • WASIX workspace qualification identifies the runtime actually compiled and uses private fixtures when committed release pins differ. Resolve independently versioned local extension archives through their product manifests. Reject mismatched portable-runtime/addon versions during synchronization and publication.
  • Cargo package tests patch local dependencies only at their matching exact version. Swift and React Native retain their exact native runtime pins throughout release packaging, including React Native's transitive pin through historical Swift metadata. Older pins use bounded, authenticated GitHub metadata requests and size/checksum-verified published Apple assets; current pins require same-run assets.
  • Android and iOS app qualification share one private fixture builder. Extension envelopes, the Swift binary target/checksum, selection-neutral source carrier and independent extension carriers all describe the current workspace runtime. Original release artifacts, extension versions and payload bytes remain intact. Exact runtime, archive, legal-member and hash validation remains enabled. Publication explicitly rejects marked extension and Swift fixtures, including when versions happen to match.
  • iOS carrier composition includes only explicitly selected extension manifests. Cached base validation checks the consumer's transitive pin and cannot depend on unrelated artifacts left on disk.

Validation:

  • Full release-tool behavior, release ownership integration, metadata, independent-version regression, formatting/lint, Swift package and React Native source suites; cold-checkout ownership/version/Swift proof; complete pinned actionlint/zizmor, 70 planner and 10 artifact-transfer tests.
  • Real Cargo consumer covering all seven independently versioned external extensions and AOT lookup; verified published native 0.3.0 Apple archives and historical Swift 0.8.0 metadata. The shared drift gate discovers SDK compatibility declarations and producer version files automatically.
  • Reproduced both mobile failures using artifacts from run 37258165389. The private fixtures pass hash and embedded runtime checks for all 39 extensions on both Android architectures, full iOS resource staging, all eight independent Swift carriers, base/bindings checksum verification, and warm-cache-to-offline Swift consumer composition. Diagnostic artifacts are not reused for hosted qualification or publication.
  • New regressions cover stale singleton pins alongside bundled contrib, preserved release artifacts, strict fixture/runtime validation, selected-only publication rejection, and ambient-artifact-independent API/CLI carrier composition. Extension packaging and declared Moon input checks also pass.

Fresh hosted qualification is still required for the final SHA's native/WASIX hosts, Apple compilation and installed mobile consumers. This PR does not mutate published versions. A corrected generated WASIX release must select a new addon version and matching TypeScript pins.

@vercel

vercel Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
oliphaunt-docs Ready Ready Preview Oct 5, 2026 6:20am UTC

@f0rr0 f0rr0 changed the title fix(wasix): align qualification with independent release pins fix(release): preserve dependency identity across SDK stages Oct 5, 2026
@f0rr0
f0rr0 marked this pull request as ready for review October 5, 2026 06:19
@f0rr0
f0rr0 force-pushed the f0rr0/fix-wasix-addon-qualification branch from e6db79a to 2f58cbb Compare October 5, 2026 06:19
@f0rr0
f0rr0 merged commit 207fcfa into main Oct 5, 2026
1 of 3 checks passed
@f0rr0
f0rr0 deleted the f0rr0/fix-wasix-addon-qualification branch October 5, 2026 06:19

This branch was successfully deployed

1 active deployment
Preview — 2f58cbba Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant