📦 deps(thirdparty): update snapshots

This commit is contained in:
ci[bot]
2026-07-20 00:03:02 +00:00
parent 47ce7f78dc
commit 2c00adccd5
1216 changed files with 10376 additions and 90058 deletions
@@ -12,6 +12,7 @@ const {
} = require("../adapters");
const { scanJson } = require("../mcp/strict-json");
const { createSkillTargetAdapter, ADAPTER_VERSION } = require("../target-adapter");
const { fsyncDirectorySync } = require("../durability");
const { inspectLayout, resolveDestination } = require("../transaction/safety");
const { validateInstance } = require("../schema-validator");
@@ -36,7 +37,7 @@ function parseOptions(argv) {
continue;
}
const key = token.slice(2);
if (["help", "override-managed-drift", "experimental-apply", "experimental-recovery", "preview-windows-output"].includes(key)) {
if (["help", "override-managed-drift", "experimental-apply", "experimental-recovery", "preview-windows-output", "require-evidence"].includes(key)) {
if (Object.hasOwn(options, key)) throw cliError("AAS_CLI_OPTION_DUPLICATE", "invalidInput", { option: key });
options[key] = true;
continue;
@@ -56,7 +57,7 @@ const COMMAND_OPTIONS = Object.freeze({
"mcp configure": new Set(["host", "scope", "config", "cache-root", "version", "runtime-integrity", "runtime-closure-digest", "backup-dir", "retention", "approve", "help"]),
"mcp backups cleanup": new Set(["config", "backup-dir", "keep", "approve", "help"]),
"stack init": new Set(["goal", "catalog-digest", "cache-root", "host", "scope", "name", "out", "preview-windows-output", "help"]),
"stack recommend": new Set(["profile", "catalog-digest", "cache-root", "help"]),
"stack create": new Set(["selection", "evidence", "artifact-dir", "require-evidence", "catalog-digest", "cache-root", "out", "preview-windows-output", "help"]),
"stack validate": new Set(["manifest", "help"]),
"stack plan": new Set(["manifest", "target", "target-root", "cache-root", "runtime-version", "runtime-integrity", "out", "override-managed-drift", "preview-windows-output", "help"]),
"stack apply": new Set(["plan", "target-root", "cache-root", "approve", "experimental-apply", "help"]),
@@ -132,8 +133,7 @@ function writeNewJson(filePath, value, { previewWindowsOutput = false } = {}) {
linked = true;
fs.unlinkSync(temporary);
try {
const parentDescriptor = fs.openSync(parent, fs.constants.O_RDONLY);
try { fs.fsyncSync(parentDescriptor); } finally { fs.closeSync(parentDescriptor); }
fsyncDirectorySync(parent);
return { outputDurability: "directorySynced", certificationStatus: "certifiable" };
} catch (error) {
if (!previewWindowsOutput) throw error;
@@ -148,6 +148,98 @@ function writeNewJson(filePath, value, { previewWindowsOutput = false } = {}) {
}
}
function writeNewStackArtifactDirectory(
directoryPath,
{ manifest, evidence },
{
previewWindowsOutput = false,
filesystem = fs,
syncDirectory = fsyncDirectorySync,
} = {},
) {
const absolute = path.resolve(directoryPath);
const parent = path.dirname(absolute);
const parentStat = filesystem.lstatSync(parent);
if (!parentStat.isDirectory() || parentStat.isSymbolicLink()) {
throw cliError("AAS_CLI_OUTPUT_PARENT_UNSAFE", "filesystem", {});
}
if (previewWindowsOutput && process.platform !== "win32") {
throw cliError("AAS_CLI_PREVIEW_WINDOWS_OUTPUT_UNSUPPORTED", "invalidInput", {});
}
try {
filesystem.lstatSync(absolute);
throw cliError("AAS_CLI_OUTPUT_EXISTS", "conflict", {});
} catch (error) {
if (error.code !== "ENOENT") throw error;
}
let stagingDirectory;
let published = false;
try {
stagingDirectory = filesystem.mkdtempSync(path.join(parent, ".aas-artifact-"));
filesystem.chmodSync(stagingDirectory, 0o700);
for (const [name, value] of [
["aas-stack.json", manifest],
["aas-selection-evidence.json", evidence],
]) {
const outputPath = path.join(stagingDirectory, name);
const descriptor = filesystem.openSync(
outputPath,
filesystem.constants.O_CREAT | filesystem.constants.O_EXCL | filesystem.constants.O_WRONLY,
0o600,
);
try {
filesystem.writeFileSync(descriptor, `${core.canonicalJson(value)}\n`);
filesystem.fsyncSync(descriptor);
} finally {
filesystem.closeSync(descriptor);
}
}
syncDirectory(stagingDirectory);
try {
filesystem.lstatSync(absolute);
throw cliError("AAS_CLI_OUTPUT_EXISTS", "conflict", {});
} catch (error) {
if (error.code !== "ENOENT") throw error;
}
// The staging directory is a sibling of the destination, so this single
// rename publishes the manifest and evidence sidecar as one filesystem
// object. Node has no portable atomic primitive for two independent paths.
filesystem.renameSync(stagingDirectory, absolute);
published = true;
stagingDirectory = undefined;
try {
syncDirectory(parent);
return { outputDurability: "directorySynced", certificationStatus: "certifiable" };
} catch (error) {
if (!previewWindowsOutput) throw error;
return { outputDurability: "fileSyncedDirectoryUnverified", certificationStatus: "notCertified" };
}
} catch (error) {
if (stagingDirectory) {
try { filesystem.rmSync(stagingDirectory, { recursive: true, force: true }); } catch {}
}
if (published) {
try {
filesystem.rmSync(absolute, { recursive: true, force: true });
syncDirectory(parent);
} catch {}
}
if (["EEXIST", "ENOTEMPTY"].includes(error.code)) {
throw cliError("AAS_CLI_OUTPUT_EXISTS", "conflict", {});
}
throw error;
}
}
function windowsOutputDurabilityDetails(written, platform = process.platform) {
if (platform !== "win32") return {};
return {
...(written.certificationStatus === "notCertified" ? { releaseProfile: "preview" } : {}),
...written,
};
}
function targetKey(target) {
return `${target.host}:${target.scope}`;
}
@@ -218,7 +310,7 @@ function buildOperations({ manifest, target, adapter, allowManagedDrift }) {
const actual = core.transaction.treeDigest(destination);
if (actual !== current.treeDigest) {
if (!allowManagedDrift) throw cliError("AAS_TRANSACTION_MANAGED_DRIFT", "drift", { skillId: skill.id });
overrides.push({ kind: "managedDrift", skillId: skill.id, reasonCodes: ["AAS_PLAN_MANAGED_DRIFT_APPROVED"], unknownFields: [] });
overrides.push({ kind: "managedDrift", skillId: skill.id, reasonCodes: ["AAS_PLAN_MANAGED_DRIFT_APPROVED"] });
}
if (actual !== sourceTreeDigest) {
operations.push({ kind: "replaceManaged", skillId: skill.id, sourceTreeDigest, expectedTreeDigest: actual, resultTreeDigest: sourceTreeDigest, backupRequired: true });
@@ -232,7 +324,7 @@ function buildOperations({ manifest, target, adapter, allowManagedDrift }) {
const actual = core.transaction.treeDigest(destination);
if (actual !== current.treeDigest) {
if (!allowManagedDrift) throw cliError("AAS_TRANSACTION_MANAGED_DRIFT", "drift", { skillId });
overrides.push({ kind: "managedDrift", skillId, reasonCodes: ["AAS_PLAN_MANAGED_DRIFT_APPROVED"], unknownFields: [] });
overrides.push({ kind: "managedDrift", skillId, reasonCodes: ["AAS_PLAN_MANAGED_DRIFT_APPROVED"] });
}
operations.push({ kind: "removeManaged", skillId, sourceTreeDigest: null, expectedTreeDigest: actual, resultTreeDigest: null, backupRequired: true });
next.delete(skillId);
@@ -245,12 +337,11 @@ async function stackInit(options) {
const host = options.host || "codex";
const scope = options.scope || "project";
const manifest = {
schemaVersion: 1,
schemaVersion: 2,
name: options.name || "aas-stack",
catalog: { package: catalog.package, version: catalog.version, integrity: catalog.digest },
targets: [{ host, scope }],
intent: { goals: [requireOption(options, "goal")] },
policy: { allowedRisk: ["none", "safe"], requireKnownSource: true, allowManualSetup: false },
profile: { goals: [requireOption(options, "goal")], languages: [], frameworks: [], constraints: [] },
skills: [],
};
const validation = core.stack.validateManifest(manifest);
@@ -262,7 +353,53 @@ async function stackInit(options) {
status: "initialized",
path: path.resolve(output),
manifestDigest: validation.manifestDigest,
...(written.certificationStatus === "notCertified" ? { releaseProfile: "preview", ...written } : {}),
...windowsOutputDurabilityDetails(written),
};
}
async function stackCreate(options) {
const catalog = await catalogFor(options);
const composed = core.composeStack(catalog, readJsonFile(requireOption(options, "selection")));
const evidencePath = options.evidence;
const artifactDirectory = options["artifact-dir"];
const auditRequested = evidencePath !== undefined || artifactDirectory !== undefined || options["require-evidence"] === true;
if (auditRequested) {
if (!evidencePath) throw cliError("AAS_CLI_EVIDENCE_REQUIRED", "invalidInput", { option: "evidence" });
if (!artifactDirectory) throw cliError("AAS_CLI_OPTION_REQUIRED", "invalidInput", { option: "artifact-dir" });
if (options.out !== undefined) {
throw cliError("AAS_CLI_OPTION_CONFLICT", "invalidInput", { options: ["artifact-dir", "out"] });
}
const evidence = readJsonFile(evidencePath);
const validation = core.validateSelectionEvidence(evidence, { catalog, manifest: composed.manifest });
if (!validation.ok) throw cliError(validation.code, validation.category, validation.details);
const written = writeNewStackArtifactDirectory(artifactDirectory, {
manifest: composed.manifest,
evidence,
}, { previewWindowsOutput: options["preview-windows-output"] === true });
const absoluteArtifactDirectory = path.resolve(artifactDirectory);
return {
ok: true,
status: "created",
selectionSource: "agent",
artifactDirectory: absoluteArtifactDirectory,
path: path.join(absoluteArtifactDirectory, "aas-stack.json"),
evidencePath: path.join(absoluteArtifactDirectory, "aas-selection-evidence.json"),
selectedSkillIds: composed.manifest.skills.map((skill) => skill.id),
manifestDigest: composed.manifestDigest,
evidenceDigest: validation.evidenceDigest,
...windowsOutputDurabilityDetails(written),
};
}
const output = options.out || "aas-stack.json";
const written = writeNewJson(output, composed.manifest, { previewWindowsOutput: options["preview-windows-output"] === true });
return {
ok: true,
status: "created",
selectionSource: "agent",
path: path.resolve(output),
selectedSkillIds: composed.manifest.skills.map((skill) => skill.id),
manifestDigest: composed.manifestDigest,
...windowsOutputDurabilityDetails(written),
};
}
@@ -275,7 +412,10 @@ async function stackPlan(options, dependencies = {}) {
throw cliError("AAS_PLAN_CATALOG_MISMATCH", "integrity", {});
}
const targetBase = selectTarget(manifest, requireOption(options, "target"));
const runtime = await verifiedRuntimeFor(options, null, dependencies);
if (options["runtime-version"] !== undefined && options["runtime-version"] !== manifest.catalog.version) {
throw cliError("AAS_PLAN_RUNTIME_CATALOG_MISMATCH", "integrity", {});
}
const runtime = await verifiedRuntimeFor({ ...options, "runtime-version": manifest.catalog.version }, null, dependencies);
if (runtime.identity.package !== manifest.catalog.package || runtime.identity.version !== manifest.catalog.version) {
throw cliError("AAS_PLAN_RUNTIME_CATALOG_MISMATCH", "integrity", {});
}
@@ -284,27 +424,14 @@ async function stackPlan(options, dependencies = {}) {
const target = { ...targetBase, adapterVersion: ADAPTER_VERSION, identityDigest: adapter.computeTargetIdentity(layout, targetBase) };
const observed = buildOperations({ manifest, target, adapter, allowManagedDrift: options["override-managed-drift"] === true });
for (const desired of manifest.skills) {
const candidate = core.getSkill(catalog, desired.id);
const assessment = core.eligibility(candidate, { policy: manifest.policy, targets: [targetBase] });
if (assessment.hardBlocked) {
throw cliError("AAS_PLAN_SKILL_POLICY_BLOCKED", "policy", { skillId: desired.id, reasonCodes: assessment.eligibilityReasonCodes });
}
if (!assessment.eligibleForRecommendation) {
observed.overrides.push({
kind: "discoveryCandidate",
skillId: desired.id,
reasonCodes: ["AAS_PLAN_DISCOVERY_CANDIDATE_VISIBLE_OVERRIDE"],
unknownFields: assessment.unknownFields,
});
}
core.getSkill(catalog, desired.id);
}
const plan = core.stack.buildPlanEnvelope({
manifest,
handshake: {
protocolVersion: core.protocolVersion,
coreVersion: core.coreVersion,
metadataSchemaVersion: core.metadataSchemaVersion,
scorerVersion: core.scorerVersion,
catalogSchemaVersion: core.catalogSchemaVersion,
},
catalog: manifest.catalog,
runtime: runtime.identity,
@@ -325,7 +452,7 @@ async function stackPlan(options, dependencies = {}) {
planDigest: plan.digest,
operationCount: plan.payload.operations.length,
out: path.resolve(options.out),
...(written.certificationStatus === "notCertified" ? { releaseProfile: "preview", ...written } : {}),
...windowsOutputDurabilityDetails(written),
};
}
@@ -339,9 +466,10 @@ function help() {
"mcp configure --host codex|claude --scope user|project --config <absolute> --cache-root <absolute> [--version <semver>] [--runtime-integrity <npm-sri> --runtime-closure-digest <sha256>] [--backup-dir <absolute>] [--approve <digest>]",
"mcp backups cleanup --config <absolute> --backup-dir <absolute> --keep <count> [--approve <digest>]",
"stack init --goal <goal> [--catalog-digest <sha256> --cache-root <absolute>] [--preview-windows-output]",
"stack recommend --profile <json> [--catalog-digest <sha256> --cache-root <absolute>]",
"stack create --selection <json> --out <aas-stack.json> [--catalog-digest <sha256> --cache-root <absolute>]",
"stack create --selection <json> --evidence <json> --artifact-dir <new-dir> --require-evidence [--catalog-digest <sha256> --cache-root <absolute>]",
"stack validate --manifest <aas-stack.json>",
"stack plan --manifest <file> --target <host:scope> --target-root <dir> --cache-root <absolute> --runtime-version <semver> --runtime-integrity <npm-sri> --out <file> [--preview-windows-output]",
"stack plan --manifest <file> --target <host:scope> --target-root <dir> --cache-root <absolute> --runtime-integrity <npm-sri> --out <file> [--preview-windows-output]",
"stack apply --experimental-apply --plan <file> --target-root <dir> --cache-root <absolute> --approve <plan-digest> (EXPERIMENTAL; NOT CERTIFIED)",
"stack doctor --plan <file> --target-root <dir> --cache-root <absolute>",
"stack recover --experimental-recovery --plan <file> --target-root <dir> --cache-root <absolute> --id <id> --action rollback|cleanup [--approve <digest>] (EXPERIMENTAL; NOT CERTIFIED)",
@@ -505,8 +633,12 @@ async function execute(argv, dependencies = {}) {
if (root === "mcp" && command === "backups" && positional[2] === "cleanup") return mcpBackupCleanup(options);
if (root !== "stack") throw cliError("AAS_CLI_COMMAND_UNKNOWN", "invalidInput", { command: root });
if (command === "init") return stackInit(options);
if (command === "recommend") return core.recommendStack(await catalogFor(options), readJsonFile(requireOption(options, "profile")));
if (command === "validate") return core.stack.validateManifest(readJsonFile(requireOption(options, "manifest")));
if (command === "create") return stackCreate(options);
if (command === "validate") {
const validation = core.stack.validateManifest(readJsonFile(requireOption(options, "manifest")));
if (!validation.ok) throw cliError(validation.code, validation.category, validation.details);
return validation;
}
if (command === "plan") return stackPlan(options, dependencies);
if (["apply", "doctor", "recover"].includes(command)) {
const plan = readJsonFile(requireOption(options, "plan"));
@@ -569,8 +701,7 @@ async function main(argv = process.argv.slice(2), io = {}) {
schemaVersion: 1,
protocolVersion: core.protocolVersion,
coreVersion: core.coreVersion,
metadataSchemaVersion: core.metadataSchemaVersion,
scorerVersion: core.scorerVersion,
catalogSchemaVersion: core.catalogSchemaVersion,
reasonCodes: [],
unknown: [],
details: {},
@@ -586,8 +717,7 @@ async function main(argv = process.argv.slice(2), io = {}) {
status: "error",
protocolVersion: core.protocolVersion,
coreVersion: core.coreVersion,
metadataSchemaVersion: core.metadataSchemaVersion,
scorerVersion: core.scorerVersion,
catalogSchemaVersion: core.catalogSchemaVersion,
code: error.code || "AAS_CLI_EXECUTION_FAILED",
category: error.category || "execution",
details: error.details || {},
@@ -610,5 +740,7 @@ module.exports = {
parseOptions,
readJsonFile,
stackPlan,
windowsOutputDurabilityDetails,
writeNewJson,
writeNewStackArtifactDirectory,
};