Pin the Node toolchain, remove runtime npm repair, make CI and E2E truthful
Template tests / tests (pull_request) Failing after 1m26s
Template tests / tests (pull_request) Failing after 1m26s
Phase 0 of the improvement plan (ai_prompts/prompt4.md): make the baseline reproducible and stop the test runner from masking real failures. - Pin Node >= 22.12 (engines + .nvmrc + engine-strict); every entry point fails fast with clear guidance instead of dying late with ERR_REQUIRE_ESM inside the packaging dependency graph. - electron-launcher.js is diagnostics-only: all runtime npm install/rebuild/ repair paths are removed. npm ci on the pinned toolchain is the only supported install path (README + GETTING_STARTED updated). - Refuse to silently launch unsandboxed on Linux: --no-sandbox now requires an explicit STEPFORGE_ALLOW_NO_SANDBOX/ELECTRON_DISABLE_SANDBOX opt-in and is otherwise a hard error with actionable fixes; user-namespace sandboxing is detected and preferred. - Click-capture E2E no longer converts startup crashes into "SKIPPED": the only allowed skip is the upfront absence of a display server. A missing shared library or crash now fails with the startup log. Same guard added to the startup smoke check. - GitHub CI: run on pull_request, pin Node from .nvmrc, drop the macOS matrix entry (not a support target), and audit production and full dependency trees as separate signals. Gitea CI: pull_request trigger + pinned Node. - Refresh package-lock on Node 22/npm 10 and remediate the form-data and undici advisories (npm audit: 0 vulnerabilities, prod and full tree). - Stop tracking generated machine-specific build reports (build/build_report.md, build/artifacts_manifest.json). Verified: 203 unit tests pass; repo-structure, startup-smoke, unit-workflows, sample-artifacts, and build-release checks pass locally with a real Electron launch. The click self-test now truthfully reports the pre-existing Linux arm/debounce capture failures (also red on Gitea CI main run 177) instead of hiding behind SKIPPED; that defect is scheduled for the capture-fix PR. Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
@@ -3,6 +3,7 @@
|
||||
|
||||
const { spawn } = require('node:child_process');
|
||||
|
||||
const { assertSupportedNode } = require('./check-node-version');
|
||||
const {
|
||||
linuxSandboxLaunchArgs,
|
||||
resolveElectronBinary,
|
||||
@@ -10,16 +11,21 @@ const {
|
||||
} = require('./electron-launcher');
|
||||
|
||||
let electronPath;
|
||||
let sandboxArgs;
|
||||
try {
|
||||
assertSupportedNode();
|
||||
electronPath = resolveElectronBinary();
|
||||
sandboxArgs = linuxSandboxLaunchArgs({ electronPath });
|
||||
} catch (error) {
|
||||
console.error(error && error.message ? error.message : error);
|
||||
process.exit(1);
|
||||
}
|
||||
const env = sanitizeElectronEnv();
|
||||
const sandboxArgs = linuxSandboxLaunchArgs({ electronPath });
|
||||
if (sandboxArgs.includes('--no-sandbox')) {
|
||||
console.warn('[stepforge] Electron sandbox helper is not configured for this install; starting with --no-sandbox');
|
||||
console.warn(
|
||||
'[stepforge] launching WITHOUT the Chromium sandbox (explicitly allowed via ' +
|
||||
'STEPFORGE_ALLOW_NO_SANDBOX/ELECTRON_DISABLE_SANDBOX — development/CI only)'
|
||||
);
|
||||
}
|
||||
|
||||
// On Linux, prefer the native Ozone path when available and enable PipeWire-
|
||||
|
||||
Reference in New Issue
Block a user