headroom/scripts/build_npm_release_assets.mjs
ninosat00 5709291914
chore(release): harden local artifact smokes (#1824)
## Description

Harden the release artifact workflow so maintainers can reproduce npm
and Python release checks locally and so OpenClaw packaging does not
depend on a not-yet-published SDK version. This follow-up also keeps the
OpenClaw loader export contract explicit and updates the PR after the
branch was merged with current `headroomlabs/main`.

## Type of Change

- [x] Bug fix (non-breaking change that fixes an issue)
- [x] New feature (non-breaking change that adds functionality)
- [x] Documentation update

## Changes Made

- Added reusable local release smoke scripts for npm assets, Python
wheel/sdist artifacts, and the combined release gate.
- Switched the release workflow npm asset build to the reusable npm
builder.
- Made OpenClaw release asset building install against the just-built
local SDK tarball before rewriting packed metadata to the release
dependency range.
- Kept the OpenClaw source dependency registry-installable at
`headroom-ai@^0.22.3` while the packed artifact still ships
`^<release-version>`.
- Added `registerHeadroomPlugin` as a named export while preserving the
default `{ register }` OpenClaw loader contract.
- Added Windows development bootstrap docs/script and regression tests
for version sync, npm asset ordering, OpenClaw source installability,
and Python wheel smoke import isolation.

## Testing

- [x] Unit tests pass (`pytest`)
- [x] New tests added for new functionality
- [x] Manual testing performed

### Test Output

```text
uv run --with pytest python -m pytest tests/test_release_workflows.py scripts/tests/test_version_sync.py -q
44 passed, 1 warning

node --check scripts/build_npm_release_assets.mjs
node --check scripts/verify_npm_release_assets.mjs

python -m py_compile scripts/build_python_release_smoke.py scripts/release_smoke_all.py scripts/version-sync.py
python scripts/verify-versions.py
All versions aligned at 0.31.0

npm ci (plugins/openclaw)
added 88 packages, audited 89 packages, found 0 vulnerabilities

python scripts/release_smoke_all.py --out release-assets-local/all-pr1824-postmerge-fixed-20260710-104739
Verified npm release assets for 0.31.0
wheel metadata OK: headroom_ai-0.31.0-cp310-abi3-win_amd64.whl contains headroom/_core.pyd
sdist License-File metadata OK: ['LICENSE', 'NOTICE']
smoke-import OK: version=0.31.0 hello=headroom-core
```

## Real Behavior Proof

- Environment: Windows 11, Python 3.14.3, Node v24.14.0, npm 11.9.0, uv
0.11.15, Rust/Cargo already installed in the local development
environment.
- Exact command / steps: Ran `python scripts/release_smoke_all.py --out
release-assets-local/all-pr1824-postmerge-fixed-20260710-104739` after
syncing this branch with current `headroomlabs/main`.
- Observed result: The command built `headroom-ai-0.31.0.tgz`,
`headroom-openclaw-0.31.0.tgz`,
`headroom_ai-0.31.0-cp310-abi3-win_amd64.whl`, and
`headroom_ai-0.31.0.tar.gz`; npm verifier passed; the wheel installed
into a fresh venv and imported `headroom._core`.
- Not tested: Full GitHub Actions release matrix and publish jobs with
real PyPI/npm/GitHub Packages credentials.

## Review Readiness

- [x] I have performed a self-review
- [x] This PR is ready for human review

## Checklist

- [x] My code follows the project's style guidelines
- [x] I have performed a self-review of my code
- [ ] I have commented my code, particularly in hard-to-understand areas
- [x] I have made corresponding changes to the documentation
- [x] My changes generate no new warnings
- [x] I have added tests that prove my fix is effective or that my
feature works
- [x] New and existing unit tests pass locally with my changes
- [ ] I have updated the CHANGELOG.md if applicable

## Screenshots (if applicable)

N/A.

## Additional Notes

The post-merge full smoke initially failed because the OpenClaw source
package depended on `headroom-ai@^0.31.0`, which is not available on
public npm yet. The builder now installs OpenClaw against the just-built
local SDK tarball before build/pack, and then rewrites packed metadata
to `^0.31.0`.

---------

Co-authored-by: JerrettDavis <mxjerrett@gmail.com>
Co-authored-by: Tejas Chopra <chopratejas@gmail.com>
2026-07-14 16:07:34 -04:00

197 lines
5.7 KiB
JavaScript

#!/usr/bin/env node
import {
existsSync,
mkdirSync,
readFileSync,
readdirSync,
rmSync,
writeFileSync,
} from "node:fs";
import path from "node:path";
import { spawnSync } from "node:child_process";
import { fileURLToPath } from "node:url";
const __dirname = path.dirname(fileURLToPath(import.meta.url));
const rootDir = path.resolve(__dirname, "..");
const sdkDir = path.join(rootDir, "sdk", "typescript");
const openClawDir = path.join(rootDir, "plugins", "openclaw");
const rawArgs = process.argv.slice(2);
const flags = new Set(rawArgs.filter((arg) => arg.startsWith("--")));
const positional = rawArgs.filter((arg) => !arg.startsWith("--"));
const [version, assetsDirArg] = positional;
if (!version || flags.has("--help") || flags.has("-h")) {
console.error(
[
"Usage: node scripts/build_npm_release_assets.mjs <version> [assets-dir] [--skip-install] [--no-verify]",
"",
"Builds the TypeScript SDK and OpenClaw npm release tarballs, rewrites",
"OpenClaw release metadata to depend on the just-built SDK version,",
"regenerates dist/package.json, and verifies the resulting assets.",
].join("\n"),
);
process.exit(flags.has("--help") || flags.has("-h") ? 0 : 2);
}
if (!/^\d+\.\d+\.\d+(?:[-+][0-9A-Za-z.-]+)?$/.test(version)) {
console.error(`Invalid version: ${version}`);
process.exit(2);
}
const timestamp = new Date().toISOString().replace(/\D/g, "").slice(0, 14);
const assetsDir = path.resolve(
rootDir,
assetsDirArg || path.join("release-assets-local", `${version}-${timestamp}`),
);
const trackedFiles = [
path.join(sdkDir, "package.json"),
path.join(sdkDir, "package-lock.json"),
path.join(openClawDir, "package.json"),
path.join(openClawDir, "package-lock.json"),
path.join(openClawDir, "dist", "package.json"),
];
const snapshots = new Map(
trackedFiles.map((filePath) => [
filePath,
existsSync(filePath) ? readFileSync(filePath, "utf8") : null,
]),
);
function quoteCmdArg(value) {
const arg = String(value);
if (/^[A-Za-z0-9_./:=\\-]+$/.test(arg)) {
return arg;
}
return `"${arg.replace(/"/g, '""')}"`;
}
function run(command, args, cwd) {
console.log(`\n> ${command} ${args.map(quoteCmdArg).join(" ")}`);
const result = spawnSync(command, args, {
cwd,
encoding: "utf8",
stdio: "inherit",
});
if (result.error) {
throw new Error(`${command} failed: ${result.error.message}`);
}
if (result.status !== 0) {
throw new Error(`${command} failed with exit code ${result.status ?? "unknown"}`);
}
}
function runNpm(args, cwd) {
if (process.platform === "win32") {
run("cmd.exe", ["/d", "/s", "/c", "npm.cmd", ...args], cwd);
return;
}
run("npm", args, cwd);
}
function runNode(args, cwd) {
run(process.execPath, args, cwd);
}
function readJson(filePath) {
return JSON.parse(readFileSync(filePath, "utf8"));
}
function writeJson(filePath, data) {
writeFileSync(filePath, `${JSON.stringify(data, null, 2)}\n`, "utf8");
}
function ensureEmptyAssetsDir() {
mkdirSync(assetsDir, { recursive: true });
const existing = readdirSync(assetsDir);
if (existing.length > 0) {
throw new Error(
`Assets directory must be empty to avoid stale tarballs: ${assetsDir}`,
);
}
}
function restoreTrackedFiles() {
for (const [filePath, contents] of snapshots.entries()) {
if (contents === null) {
rmSync(filePath, { force: true });
} else {
mkdirSync(path.dirname(filePath), { recursive: true });
writeFileSync(filePath, contents, "utf8");
}
}
}
function relativeFileSpec(fromDir, targetPath) {
let relativePath = path.relative(fromDir, targetPath).split(path.sep).join("/");
if (!relativePath.startsWith(".")) {
relativePath = `./${relativePath}`;
}
return `file:${relativePath}`;
}
function rewriteOpenClawDependency(spec) {
const packageJsonPath = path.join(openClawDir, "package.json");
const pkg = readJson(packageJsonPath);
pkg.dependencies = pkg.dependencies || {};
pkg.dependencies["headroom-ai"] = spec;
writeJson(packageJsonPath, pkg);
}
function rewriteOpenClawLocalDependency(sdkTarballPath) {
rewriteOpenClawDependency(relativeFileSpec(openClawDir, sdkTarballPath));
}
function rewriteOpenClawReleaseDependency() {
rewriteOpenClawDependency(`^${version}`);
}
function assertTarballBuilt(name) {
const tarballPath = path.join(assetsDir, `${name}-${version}.tgz`);
if (!existsSync(tarballPath)) {
throw new Error(`Expected npm pack to produce ${tarballPath}`);
}
return tarballPath;
}
try {
ensureEmptyAssetsDir();
if (!flags.has("--skip-install")) {
runNpm(["ci"], sdkDir);
}
runNpm(["run", "build"], sdkDir);
runNpm(["version", version, "--no-git-tag-version", "--allow-same-version"], sdkDir);
runNpm(["pack", "--pack-destination", assetsDir], sdkDir);
const sdkTarballPath = assertTarballBuilt("headroom-ai");
rewriteOpenClawLocalDependency(sdkTarballPath);
if (!flags.has("--skip-install")) {
runNpm(
["install", "--package-lock=false", "--no-audit", "--no-fund", "--ignore-scripts"],
openClawDir,
);
} else {
runNpm(["install", "--no-save", "--package-lock=false", sdkTarballPath], openClawDir);
}
runNpm(["run", "build"], openClawDir);
runNpm(["version", version, "--no-git-tag-version", "--allow-same-version"], openClawDir);
rewriteOpenClawReleaseDependency();
runNode(["prepare-dist.mjs"], openClawDir);
runNpm(["pack", "--pack-destination", assetsDir], openClawDir);
assertTarballBuilt("headroom-openclaw");
if (!flags.has("--no-verify")) {
runNode(["scripts/verify_npm_release_assets.mjs", assetsDir, version], rootDir);
}
console.log(`\nBuilt and verified npm release assets in ${assetsDir}`);
} finally {
restoreTrackedFiles();
runNode(["prepare-dist.mjs"], openClawDir);
}