From 886dddb9ee87f59b524b3d90b1b6870eddc6f042 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 7 Oct 2026 21:17:39 +0000 Subject: [PATCH] Support vlt 1.3.0-1.3.7 to green the nightly canary The vlt nightly canary has been red on main every night since 2026-10-04: its release watchdog fails because npm publishes vlt 1.3.0 ... 1.3.7, which the Releases table neither supports nor excludes. The capstones themselves passed on vlt@latest (1.3.x) on Linux, macOS and Windows every one of those nights. All five capstones (e2e_redirect_vlt_build, e2e_vendor_vlt_build, mode_migration_vlt, e2e_safety_vlt, e2e_vlt) pass on each of 1.3.0 ... 1.3.7 on Linux with check-vlt-legs clean, and every release still writes lockfileVersion 1 with era F grammar. List them as supported, extend era F to 1.3.7, regenerate the leg manifest with check-vlt-legs.py --derive, and pin their registry integrity in vlt-historical-integrity.json (each tarball re-hashed and checked against dist.integrity). The harness test that used 1.3.0 as its unlisted example now uses 9.9.9. Claude-Session: https://claude.ai/code/session_01CvCSdYG1Nk8Ys2T2mZr9Z7 Co-Authored-By: Claude Opus 5.5 (1M context) --- crates/socket-patch-cli/tests/vlt-leg-manifest.json | 10 +++++++++- docs/testing/vlt-compatibility.md | 11 +++++++---- scripts/tests/test_backtest_harnesses.py | 11 ++++++----- scripts/vlt-historical-integrity.json | 10 +++++++++- 4 files changed, 31 insertions(+), 11 deletions(-) diff --git a/crates/socket-patch-cli/tests/vlt-leg-manifest.json b/crates/socket-patch-cli/tests/vlt-leg-manifest.json index 09f210274..4c82a2489 100644 --- a/crates/socket-patch-cli/tests/vlt-leg-manifest.json +++ b/crates/socket-patch-cli/tests/vlt-leg-manifest.json @@ -962,7 +962,15 @@ "1.0.10", "1.1.0", "1.1.1", - "1.2.0" + "1.2.0", + "1.3.0", + "1.3.1", + "1.3.2", + "1.3.3", + "1.3.4", + "1.3.5", + "1.3.6", + "1.3.7" ], "excluded": [ "0.0.0-0", diff --git a/docs/testing/vlt-compatibility.md b/docs/testing/vlt-compatibility.md index 1deecfb54..57f4332bc 100644 --- a/docs/testing/vlt-compatibility.md +++ b/docs/testing/vlt-compatibility.md @@ -18,7 +18,7 @@ vlt project, and the caveats users meet, are in | C | 1.0.0-rc.15 … 1.0.0-rc.32 | `1` | `~` / `+` + `_x` escapes (`~npm~name@ver`), `peer.N` | absent | | D | 1.0.0-rc.33 … 1.0.7 | `1` | as C | the registry URL | | E | 1.0.8 … 1.1.1 | `1` | as C, `peer.<16 hex>` | the registry URL | -| F | 1.2.0 | `1` | as E; the global store (`store-linker`) | the registry URL | +| F | 1.2.0 … 1.3.7 | `1` | as E; the global store (`store-linker`) | the registry URL | On every release that writes slot [3], it is omitted when the project configures `registry` and the node's tarball URL starts with it (vlt's @@ -203,15 +203,18 @@ toolchain problem a failure, and so does `CI=true` with `_JS` unset. | supported | `1.0.0-rc.1`, `1.0.0-rc.2`, `1.0.0-rc.3`, `1.0.0-rc.4`, `1.0.0-rc.5`, `1.0.0-rc.6`, `1.0.0-rc.7`, `1.0.0-rc.8`, `1.0.0-rc.9`, `1.0.0-rc.10`, `1.0.0-rc.11`, `1.0.0-rc.12`, `1.0.0-rc.13`, `1.0.0-rc.14`, `1.0.0-rc.15`, `1.0.0-rc.16`, `1.0.0-rc.17`, `1.0.0-rc.18` | | supported | `1.0.0-rc.22`, `1.0.0-rc.23`, `1.0.0-rc.24`, `1.0.0-rc.25`, `1.0.0-rc.26`, `1.0.0-rc.27`, `1.0.0-rc.28`, `1.0.0-rc.29`, `1.0.0-rc.30`, `1.0.0-rc.31`, `1.0.0-rc.32`, `1.0.0-rc.33`, `1.0.0-rc.34` | | supported | `1.0.1`, `1.0.2`, `1.0.3`, `1.0.4`, `1.0.5`, `1.0.6`, `1.0.7`, `1.0.8`, `1.0.9`, `1.0.10`, `1.1.0`, `1.1.1`, `1.2.0` | +| supported | `1.3.0`, `1.3.1`, `1.3.2`, `1.3.3`, `1.3.4`, `1.3.5`, `1.3.6`, `1.3.7` | | excluded (broken install) | `0.0.0-0` | | excluded (Deno-compiled wrappers) | `0.0.0-2`, `0.0.0-3`, `0.0.0-4`, `0.0.0-5`, `0.0.0-6`, `0.0.0-7`, `0.0.0-8`, `0.0.0-9`, `0.0.0-10` | | excluded (`vlt install` exits 13 on Node 24 after "Done") | `0.0.0-22` | | excluded (never published) | `1.0.0-rc.19`, `1.0.0-rc.20`, `1.0.0-rc.21` | | excluded (unrelated 2017 publishes) | `0.0.1`, `1.0.0` | -`0.0.0-0.` builds are excluded too. Every supported release was -run through all five capstones on macOS during SP-9 (the CI matrix samples -them per OS). +`0.0.0-0.` builds are excluded too. Every supported release +through 1.2.0 was run through all five capstones on macOS during SP-9; +1.3.0 … 1.3.7 were run through them on Linux, and the nightly canary ran +1.3.x `vlt@latest` through them on Linux, macOS and Windows (the CI matrix +samples them per OS). ## Leg inventory diff --git a/scripts/tests/test_backtest_harnesses.py b/scripts/tests/test_backtest_harnesses.py index e0e380536..bf54f2cbd 100644 --- a/scripts/tests/test_backtest_harnesses.py +++ b/scripts/tests/test_backtest_harnesses.py @@ -753,9 +753,9 @@ def test_exclusions(self): for version in vlt.VERSIONS: self.assertEqual(vlt.release_status(version, self.supported, self.excluded), 'supported') - self.assertEqual(vlt.release_status('1.3.0', self.supported, self.excluded), 'unlisted') - self.assertEqual(vlt.unlisted_releases(['1.2.0', '0.0.0-22', '1.3.0', '0.0.0-0.17'], - self.supported, self.excluded), ['1.3.0']) + self.assertEqual(vlt.release_status('9.9.9', self.supported, self.excluded), 'unlisted') + self.assertEqual(vlt.unlisted_releases(['1.3.7', '0.0.0-22', '9.9.9', '0.0.0-0.17'], + self.supported, self.excluded), ['9.9.9']) def test_main_refuses_an_excluded_release(self): with self.assertRaises(SystemExit), patch('sys.stderr'): @@ -770,9 +770,10 @@ def test_versions_order_and_eras(self): '1.2.0']) eras = {v: vlt.era_of(v) for v in ('0.0.0-18', '0.0.0-19', '1.0.0-rc.8', '1.0.0-rc.9', '1.0.0-rc.14', '1.0.0-rc.15', '1.0.0-rc.32', - '1.0.0-rc.33', '1.0.7', '1.0.8', '1.1.1', '1.2.0')} + '1.0.0-rc.33', '1.0.7', '1.0.8', '1.1.1', '1.2.0', + '1.3.7')} self.assertEqual(list(eras.values()), - ['A0', 'A', 'A', 'B', 'B', 'C', 'C', 'D', 'D', 'E', 'E', 'F']) + ['A0', 'A', 'A', 'B', 'B', 'C', 'C', 'D', 'D', 'E', 'E', 'F', 'F']) def test_pinned_integrity_covers_every_supported_release(self): pinned = json.loads(vlt.HISTORICAL_INTEGRITY.read_text()) diff --git a/scripts/vlt-historical-integrity.json b/scripts/vlt-historical-integrity.json index b859e4043..d337467d4 100644 --- a/scripts/vlt-historical-integrity.json +++ b/scripts/vlt-historical-integrity.json @@ -64,5 +64,13 @@ "1.0.10": "sha512-yawzDKPtzO8a8Sa3b4Kxe5/f2HFhlYasmjPZX/8iqWV3t6vlelhKDKsK3+vvzetf3xDNEkyQoHgp/mQc5Q6GpQ==", "1.1.0": "sha512-Udlf9V9La9uE6ROgHoglIo1is2fH4uAMneLfVU1P/hbJH/y7FfHankLd7tc/+O8JZHiWDQNunG1ys5Csyp7CTA==", "1.1.1": "sha512-kLDMPqK7LrqJ19xmFIVKrf03F7SCTZpXJ8M0Qm4qd3ftnb8pXvyPmwO1hmFwMOm3TO1TH4J7qbKdE7KkkVo2pw==", - "1.2.0": "sha512-t7ONkM8YgRlY0g+6l+OU4oS2WS/dp7DK/vmFwNqxA0D+ehPWprNOTTH3uUYURAnCg5lr9vzJSmX9nNCcG5xGXA==" + "1.2.0": "sha512-t7ONkM8YgRlY0g+6l+OU4oS2WS/dp7DK/vmFwNqxA0D+ehPWprNOTTH3uUYURAnCg5lr9vzJSmX9nNCcG5xGXA==", + "1.3.0": "sha512-Z4drBAkOA8JeBUKyfrTgnOx5CuvttuD9r9T9YUHUUOORtIS2yiVm2zZGq7GJ7qRaaf7KR7Fa6r0S3H98PISDoA==", + "1.3.1": "sha512-j9/ncs54sE9lvmsPQVruc5xKZ8xsuXqnBT/W3dCVUH1vq9ikT3wwt+MeoRcDqA5kC57jyNN+N0l4n+Ctkk6m/w==", + "1.3.2": "sha512-xA8N7NNaKp07v5+WhqyROS0LtVjEtc28kYQKQw0CNpoO/Q8tGnA5By+ulHdIv7U86k+9Da27zdy5UGnZsLyjgw==", + "1.3.3": "sha512-M5EsGzoHbMudvJyJmIeImAlCLnoz7gEGg3mPwOYIAsz1tMUZ2a4ffkD1F3WUgLUtiSEjnNFUJm3Iwr7fFfWH8Q==", + "1.3.4": "sha512-W9d0LfZbGltW4la6U4YZnEDEnNyu2OVRnqTuKRCfjY+ck5BB/7b8bQmmk+J4RHZ94U7OT+GepU1og5p8o6QE0g==", + "1.3.5": "sha512-UR4yVcULH9vccyatHI+rU5gTI1rdWcJKYMuLkXI5O18q6hsUoCiEGqBxqPbFDFROsEhkBAOkGCFDVyGd2RqRfg==", + "1.3.6": "sha512-ooaGujc9YBedp6OOIbDc8OvCaUEvwjwgMEJji1NySzVdfd3u6d0q90Sey4IEYctGUD249LSOxyE/+6aG4QvqWw==", + "1.3.7": "sha512-ULCK3PDWY6HTkle9+OLyNbfqyA9xW1b6HVgYVIlPu/hbJFFizrionsNUpffSc+BS3VD842GfzslvRzX3y+5B6g==" }