From ef00e43863e6d248f27a43bb2be0aae4a9c98153 Mon Sep 17 00:00:00 2001 From: systemfsoftware-maker Date: Thu, 8 Oct 2026 00:38:45 +0000 Subject: [PATCH 1/2] build(release): put the pinned pnpm in the dev shell the release workflow runs The reusable release workflow runs github-release-management plan through nix develop. Its workspace reader spawns pnpm ls and pnpm config get, and the dev shell had no pnpm. On the runner the spawn failed, which the reader reports as manifest-unreadable at the repository root (Release run 37706216051). pnpm_11 is the pnpm the workspace tarballs build with, and mkPnpmWorkspacePackages refuses evaluation unless packageManager pins that exact version. Verdict-Semantics: unchanged --- flake.nix | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/flake.nix b/flake.nix index b458e5c7..91ddea14 100644 --- a/flake.nix +++ b/flake.nix @@ -71,9 +71,10 @@ assert clashes == [ ] || throw "flake.nix: workspace packages ${lib.concatStringsSep ", " clashes} collide with flake packages"; workspace // own); - # pnpm is deliberately absent: `packageManager` pins pnpm@11.27.0 and - # corepack is the one thing allowed to resolve it. A second pnpm on PATH - # would answer `pnpm install` with a version the lockfile never saw. + # pnpm_11 is the pnpm `workspaceOf` builds with, and mkPnpmWorkspacePackages + # fails evaluation unless `packageManager` pins that exact version, so the + # shell's pnpm is the pinned one. The reusable release workflow needs it: + # its workspace reader spawns `pnpm ls` and `pnpm config get`. devShells = forEachSystem (pkgs: { default = pkgs.mkShell { packages = [ @@ -83,6 +84,7 @@ pkgs.nodejs_24 pkgs.deno pkgs.process-compose + pkgs.pnpm_11 # version-management and github-release-management, which the # reusable release workflow runs through `nix develop --command` pnpm-release-management.packages.${pkgs.stdenv.hostPlatform.system}.release-tools From 9f6903dfdcbbe45124b7c5080541bb07d44bd8f8 Mon Sep 17 00:00:00 2001 From: systemfsoftware-maker Date: Thu, 8 Oct 2026 00:39:13 +0000 Subject: [PATCH 2/2] ci(repo): run the release plan phase on the PR runner as evidence Temporary: reverted in the next commit once the reading is recorded. --- .github/workflows/nix.yml | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/.github/workflows/nix.yml b/.github/workflows/nix.yml index 68105cfd..a6f148fb 100644 --- a/.github/workflows/nix.yml +++ b/.github/workflows/nix.yml @@ -65,3 +65,25 @@ jobs: exit 1 fi grep -q 'tarball CHANGELOG.md differs' sabotage.log + + release-plan-evidence: + name: release plan phase through the dev shell (temporary evidence) + runs-on: ubuntu-latest + timeout-minutes: 60 + steps: + - uses: actions/checkout@v7 + with: + fetch-depth: 0 + fetch-tags: true + - uses: cachix/install-nix-action@v31 + - name: Pack the workspace through the caller's flake + run: echo "TARBALLS=$(nix build --no-link --print-out-paths .#workspace-tarballs)" >> "$GITHUB_ENV" + - id: plan + name: Decide release phase from repository state + env: + GITHUB_TOKEN: ${{ github.token }} + run: | + echo "host pnpm: $(command -v pnpm || echo absent)" + nix develop --command pnpm --version + nix develop --command github-release-management plan --tarballs "$TARBALLS" --output "$GITHUB_OUTPUT" + - run: echo "phase=${{ steps.plan.outputs.phase }} pending_intents=${{ steps.plan.outputs.pending_intents }}"