feat(prx): beadsd-box OCI image + CI publish workflow (prx-634)#754
Merged
Conversation
Contributor
Code Coverage OverviewLanguages: TypeScript TypeScript / unitThe overall coverage in the branch remains at 88%, unchanged from the branch. Show a code coverage summary of the most impacted files.
Updated |
| // (attest + store the L2; the daemon remembers it so the box's writes auto-link). | ||
| // Best-effort attest: a failure surfaces as null but never tears the pod down. | ||
| import { describe, test, expect } from "bun:test"; | ||
| import { describe, test, expect, afterEach } from "bun:test"; |
Replace all direct zod schema object usages with the new explicit type + parse-function surface from @bounded-systems/machine-schema@0.3.0: - handoff/cli.ts: handoffTargetActor.safeParse → safeParseHandoffTargetActor; handoffTargetActor.options → HANDOFF_TARGET_ACTOR_VALUES (3 call sites) - handoff/store.ts: handoffEnvelope.parse → parseHandoffEnvelope (4 call sites) - derive/cli.ts: z.array(rawStateV1Schema) → z.array(z.unknown().transform(parseRawStateV1)) - machine/contracts/guards.ts: rawStateV1Schema.parse → parseRawStateV1 - machine/contracts/anchored-chain-bridge.ts: rawStateV1Schema → z.unknown().transform(parseRawStateV1) - pr-state/domain_state.ts: .shape.* → z.custom<T>(); rawStateV1Schema.parse → z.unknown().transform(parseRawStateV1) + parseRawStateV1 - machine/work_unit.ts: update brand comment (v0.3.0 uses unique-symbol brand, not zod BRAND — explicit `as WorkUnitId` casts remain correct) Dependency: @bounded-systems/machine-schema@^0.3.0 (published separately). CI is blocked until that package is available on JSR. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…LaunchDigest on Mac) (#749) virtiofs forwards file semantics but not Unix socket semantics: the keeperd.sock file appears on the macOS filesystem but connections from the Mac host fail with ENOENT. TCP tunnels around this — keeperd-room declares tcpPort: 9999, podman publishes -p 9999:9999 and passes --port 9999 as a CMD arg, and launchPod sets KEEPERD_HOST=127.0.0.1:9999 so door-kit's client connects via TCP instead of the Unix socket path. launchPod falls back to KEEPERD_SOCK (Unix) when tcpPort is absent, so the Linux production path is unchanged. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Adds publish-oci-boxes.yml — builds beadsd-box via nix on an aarch64-linux runner (ubuntu-24.04-arm, same arch as Mac M-series podman machine) and pushes to ghcr.io/bounded-systems/prx/beadsd-box with a digest-file so the SHA can be pinned in beadsd-room.ts. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Publishes ghcr.io/bounded-systems/prx/beadsd-box (aarch64-linux, nix streamLayeredImage) and pins its digest in beadsd-room.ts so podman pulls an immutable, content-addressed image instead of the placeholder "beadsd-box" string. Also exports BEADSD_ROOM_IMAGE from beadsd-room.ts (matching KEEPERD_ROOM_IMAGE pattern) so the podman test stays in sync without hardcoding the full reference. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Regenerate after the package.json bump in 4b1e551 was not matched by a lockfile update at the time. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…ft pin
- anchored-chain-bridge: `import type {z}` → `import {z}` (z used as value
in defaultMachineSchemaMap); replace `z.unknown().transform(parseRawStateV1)`
with a ZodObject + `.refine()` so the drift-pin test can introspect required
keys (Zod v4 .transform() creates ZodPipe, .refine() stays ZodObject)
- envelope.test.ts: rewrite for v0.3.0 API (parseHandoffEnvelope /
HANDOFF_TARGET_ACTOR_VALUES replace removed Zod schema exports)
- sprint.test.ts: use canonicalWorkUnitIdSchema.parse() instead of
WorkUnitId cast — Zod v4 brand is $brand<"WorkUnitId"> not symbol-brand
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
podman-runtime.ts has crossed the 85% per-file threshold; remove from the allow-below-85 list per the ratchet rule (baseline only shrinks). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
a2d7d07 to
5158ad8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
beadsd-boxOCI image vianix dockerTools.streamLayeredImage(prx, bd, dolt, gitMinimal, cacert — entrypointprx beads serve)ghcr.io/bounded-systems/prx/beadsd-boxto GHCR (aarch64-linux, same arch as Mac M-series podman machine)beadsd-room.tsso podman pulls an immutable, content-addressed imageBEADSD_ROOM_IMAGEconstant (matchesKEEPERD_ROOM_IMAGEpattern) — test stays in sync without hardcodingpublish-oci-boxes.ymlCI workflow: triggers onpush: tags v*andworkflow_dispatch; builds onubuntu-24.04-arm(native aarch64-linux), pushes to GHCR with--digestfile, outputs digest in step summary for future repinsTest plan
bun test packages/prx/test/room/— 80/80 passghcr.io/bounded-systems/prx/beadsd-box@sha256:b080ac973799c724f181df08b01de26c55d5a29d7f94fd54ba0cb1dd8cb57173🤖 Generated with Claude Code