[E00-S01-T13] Clean clone installs with frozen lockfile #166

Closed
opened 2026-08-27 00:06:39 +00:00 by kpcto · 8 comments
Owner

Parent story: [E00-S01] Workspace bootstrap (#58)

Intent

Ensure a clean clone installs successfully using a frozen lockfile.

Acceptance criteria

  • a clean clone installs with a frozen lockfile
  • the frozen install completes without resolving new versions

Explicitly out of scope

  • root build/test/typecheck commands (E00-S01-T12)
  • no core imports a concrete extension (E00-S01-T14)

Test plan

  • run pnpm install --frozen-lockfile from a clean clone

Rollback note

  • revert the lockfile or manifest changes

Owning stream

platform

Risk quadrant

agent-full

> Parent story: [E00-S01] Workspace bootstrap (#58) ## Intent Ensure a clean clone installs successfully using a frozen lockfile. ## Acceptance criteria - a clean clone installs with a frozen lockfile - the frozen install completes without resolving new versions ## Explicitly out of scope - root build/test/typecheck commands (E00-S01-T12) - no core imports a concrete extension (E00-S01-T14) ## Test plan - run `pnpm install --frozen-lockfile` from a clean clone ## Rollback note - revert the lockfile or manifest changes ### Owning stream platform ### Risk quadrant agent-full
kpcto added this to the Sprint 0 milestone 2026-08-27 00:06:39 +00:00
kpcto added the
status
ready
kind
task
labels 2026-08-27 00:06:39 +00:00
bot-dispatcher added
status
proposed
and removed
status
ready
kind
task
labels 2026-08-27 00:06:41 +00:00
Member

Auto-reverted by dispatcher: DoR lint: required section "Intent" is empty; required section "Acceptance criteria" is empty; required section "Explicitly out of scope" is empty; required section "Test plan" is empty; required section "Rollback note" is empty; acceptance criteria: no bullet assertions found

status/ready may only be applied by a human maintainer.

> Auto-reverted by dispatcher: DoR lint: required section "Intent" is empty; required section "Acceptance criteria" is empty; required section "Explicitly out of scope" is empty; required section "Test plan" is empty; required section "Rollback note" is empty; acceptance criteria: no bullet assertions found `status/ready` may only be applied by a human maintainer.
kpcto added the
kind
task
label 2026-08-27 21:24:09 +00:00
kpcto added
status
ready
and removed
status
proposed
labels 2026-08-28 23:01:59 +00:00
bot-dispatcher added
loop
1
status
in-progress
and removed
status
ready
labels 2026-08-28 23:02:09 +00:00
Member
agent: dispatcher
phase: complete
plan_summary: Dispatch #166: [E00-S01-T13] Clean clone installs with frozen lockfile (platform)
```yaml agent: dispatcher phase: complete plan_summary: Dispatch #166: [E00-S01-T13] Clean clone installs with frozen lockfile (platform) ```
Member
agent: implementer
phase: start
issue: "166"
objective: "[E00-S01-T13] Clean clone installs with frozen lockfile"
plan_summary: >
  Add tests/frozen-install.test.mjs that simulates a clean clone (git clone of
  the committed tree), runs `corepack pnpm install --frozen-lockfile`, and
  asserts (1) install exits 0, (2) the committed pnpm-lock.yaml is untouched,
  and (3) the installed tree matches the lockfile exactly (no new versions
  resolved). Open PR on feature/166 with a criterion→test table; CI green.
skills: [gitea-protocol, conventions, testing]
```yaml agent: implementer phase: start issue: "166" objective: "[E00-S01-T13] Clean clone installs with frozen lockfile" plan_summary: > Add tests/frozen-install.test.mjs that simulates a clean clone (git clone of the committed tree), runs `corepack pnpm install --frozen-lockfile`, and asserts (1) install exits 0, (2) the committed pnpm-lock.yaml is untouched, and (3) the installed tree matches the lockfile exactly (no new versions resolved). Open PR on feature/166 with a criterion→test table; CI green. skills: [gitea-protocol, conventions, testing] ```
Member
agent: reviewer
verdict: approve
```yaml agent: reviewer verdict: approve ```
bot-dispatcher added
status
review
and removed
status
in-progress
loop
1
kind
task
labels 2026-08-28 23:11:44 +00:00
Member
agent: reviewer
verdict: approve
findings:
  - file: tests/frozen-install.test.mjs:1
    severity: nit
    description: Consider adding a brief comment at the top of the file explaining what the test validates for future maintainers
  - file: tests/frozen-install.test.mjs:100
    severity: nit
    description: The timeout values (60_000, 300_000) could be defined as constants for better readability
```yaml agent: reviewer verdict: approve findings: - file: tests/frozen-install.test.mjs:1 severity: nit description: Consider adding a brief comment at the top of the file explaining what the test validates for future maintainers - file: tests/frozen-install.test.mjs:100 severity: nit description: The timeout values (60_000, 300_000) could be defined as constants for better readability ```
bot-dispatcher added
status
review
and removed
status
review
labels 2026-08-28 23:11:55 +00:00
Member
agent: implementer
phase: complete
issue: "166"
objective: "[E00-S01-T13] Clean clone installs with frozen lockfile"
result_summary: >
  Added tests/frozen-install.test.mjs (5 tests): simulates a clean clone (git
  clone of the committed tree into a temp dir), runs
  `corepack pnpm install --frozen-lockfile`, and asserts exit 0, populated
  node_modules/.pnpm, "Lockfile is up to date, resolution step is skipped",
  byte-identical pnpm-lock.yaml after install, and installed-tree/lockfile
  parity (every packages: entry present, no extra versions) plus locked
  TypeScript 6.0.3 resolution and a non-vacuous helper probe.
evidence:
  - "PR #380 open: [E00-S01-T13] Clean clone installs with frozen lockfile"
  - "CI green: run #57 'Frozen lockfile install' success (5/5 steps), commit status success"
  - "Full suite on Node 24: 47/47 pass (42 pre-existing + 5 new)"
  - "Mutation probe: stale lockfile (left-pad added, lockfile untouched) fails frozen install, as the suite requires"
notes: >
  No manifest/lockfile changes were needed — the committed pnpm-lock.yaml was
  already in sync; the change is the regression suite that makes the
  acceptance criteria enforceable. Out of scope per brief: root commands
  (E00-S01-T12), extension-import boundary (E00-S01-T14).
```yaml agent: implementer phase: complete issue: "166" objective: "[E00-S01-T13] Clean clone installs with frozen lockfile" result_summary: > Added tests/frozen-install.test.mjs (5 tests): simulates a clean clone (git clone of the committed tree into a temp dir), runs `corepack pnpm install --frozen-lockfile`, and asserts exit 0, populated node_modules/.pnpm, "Lockfile is up to date, resolution step is skipped", byte-identical pnpm-lock.yaml after install, and installed-tree/lockfile parity (every packages: entry present, no extra versions) plus locked TypeScript 6.0.3 resolution and a non-vacuous helper probe. evidence: - "PR #380 open: [E00-S01-T13] Clean clone installs with frozen lockfile" - "CI green: run #57 'Frozen lockfile install' success (5/5 steps), commit status success" - "Full suite on Node 24: 47/47 pass (42 pre-existing + 5 new)" - "Mutation probe: stale lockfile (left-pad added, lockfile untouched) fails frozen install, as the suite requires" notes: > No manifest/lockfile changes were needed — the committed pnpm-lock.yaml was already in sync; the change is the regression suite that makes the acceptance criteria enforceable. Out of scope per brief: root commands (E00-S01-T12), extension-import boundary (E00-S01-T14). ```
Member
agent: tester
phase: start
issue: "166"
objective: "Independently probe PR #380: [E00-S01-T13] clean clone installs with a frozen lockfile"
plan_summary: >
  Verify both acceptance criteria independently of the implementer's own run:
  (1) a clean clone installs with `pnpm install --frozen-lockfile` (exit 0,
  node_modules/.pnpm populated) and (2) the frozen install completes without
  resolving new versions (pnpm reports "Lockfile is up to date, resolution step
  is skipped", pnpm-lock.yaml byte-identical before/after, virtual store matches
  the lockfile packages: section). Then run the PR's new
  tests/frozen-install.test.mjs suite and cross-check CI run #57 job #69 logs.
skills: [gitea-protocol, testing]
```yaml agent: tester phase: start issue: "166" objective: "Independently probe PR #380: [E00-S01-T13] clean clone installs with a frozen lockfile" plan_summary: > Verify both acceptance criteria independently of the implementer's own run: (1) a clean clone installs with `pnpm install --frozen-lockfile` (exit 0, node_modules/.pnpm populated) and (2) the frozen install completes without resolving new versions (pnpm reports "Lockfile is up to date, resolution step is skipped", pnpm-lock.yaml byte-identical before/after, virtual store matches the lockfile packages: section). Then run the PR's new tests/frozen-install.test.mjs suite and cross-check CI run #57 job #69 logs. skills: [gitea-protocol, testing] ```
kpcto closed this issue 2026-08-28 23:16:25 +00:00
kpcto added
kind
task
status
done
and removed
status
review
labels 2026-08-28 23:16:26 +00:00
Member
agent: tester
phase: complete
issue: "166"
verdict: pass
objective: "Independently probe PR #380: [E00-S01-T13] clean clone installs with a frozen lockfile"
result_summary: >
  Both acceptance criteria verified independently on Node v24.20.0 with pnpm
  11.23.0 via corepack, against a clean `git clone` of the committed feature/166
  tree (no node_modules, no untracked files):
  (1) a clean clone installs with a frozen lockfile — `pnpm install
  --frozen-lockfile` exits 0 and populates node_modules/.pnpm (typescript@6.0.3);
  (2) the frozen install completes without resolving new versions — pnpm reports
  "Lockfile is up to date, resolution step is skipped", pnpm-lock.yaml is
  byte-identical before/after (sha256 a21bd7e9…), and the virtual store holds
  exactly the locked package set. PR's new suite passes 5/5 and the full suite
  passes 47/47. A mutation probe (add left-pad@1.3.0 without updating the
  lockfile) makes the frozen install fail with ERR_PNPM_OUTDATED_LOCKFILE,
  confirming the frozen install never silently resolves new versions.
evidence:
  - "Clean clone + `corepack pnpm install --frozen-lockfile` on Node v24.20.0 → exit 0; 'Lockfile is up to date, resolution step is skipped'; 'Done in 14.3s using pnpm v11.23.0'; + typescript 6.0.3"
  - "pnpm-lock.yaml sha256 identical before/after install (a21bd7e9fea7910c58fd774eb0fb9f8968809289c11b768fc6d3372684fab153); `git status` clean after install"
  - "node_modules/.pnpm contains exactly typescript@6.0.3 (the single locked package); `corepack pnpm exec tsc --version` → Version 6.0.3"
  - "PR's tests/frozen-install.test.mjs: 5/5 pass (node --test, Node v24.20.0)"
  - "Full suite `node --test tests/**/*.test.mjs`: 47/47 pass (42 pre-existing + 5 new)"
  - "Mutation probe: + left-pad@1.3.0 (lockfile untouched) → frozen install exits 1 ERR_PNPM_OUTDATED_LOCKFILE, lockfile byte-unchanged"
ci_links:
  - pr: http://gitea:3000/Fabrika/PersonalBlog/pulls/380
  - run: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/57
  - job: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/57/jobs/69
notes: >
  On Node v22.23.2 (below the pinned engine floor >=24 <25) the frozen install
  correctly fails with ERR_PNPM_UNSUPPORTED_ENGINE — the E00-S01-T08 engine
  restriction is enforced; the acceptance path requires Node 24, matching CI and
  the docs. No repo files (including the implementer's tests) were modified.
```yaml agent: tester phase: complete issue: "166" verdict: pass objective: "Independently probe PR #380: [E00-S01-T13] clean clone installs with a frozen lockfile" result_summary: > Both acceptance criteria verified independently on Node v24.20.0 with pnpm 11.23.0 via corepack, against a clean `git clone` of the committed feature/166 tree (no node_modules, no untracked files): (1) a clean clone installs with a frozen lockfile — `pnpm install --frozen-lockfile` exits 0 and populates node_modules/.pnpm (typescript@6.0.3); (2) the frozen install completes without resolving new versions — pnpm reports "Lockfile is up to date, resolution step is skipped", pnpm-lock.yaml is byte-identical before/after (sha256 a21bd7e9…), and the virtual store holds exactly the locked package set. PR's new suite passes 5/5 and the full suite passes 47/47. A mutation probe (add left-pad@1.3.0 without updating the lockfile) makes the frozen install fail with ERR_PNPM_OUTDATED_LOCKFILE, confirming the frozen install never silently resolves new versions. evidence: - "Clean clone + `corepack pnpm install --frozen-lockfile` on Node v24.20.0 → exit 0; 'Lockfile is up to date, resolution step is skipped'; 'Done in 14.3s using pnpm v11.23.0'; + typescript 6.0.3" - "pnpm-lock.yaml sha256 identical before/after install (a21bd7e9fea7910c58fd774eb0fb9f8968809289c11b768fc6d3372684fab153); `git status` clean after install" - "node_modules/.pnpm contains exactly typescript@6.0.3 (the single locked package); `corepack pnpm exec tsc --version` → Version 6.0.3" - "PR's tests/frozen-install.test.mjs: 5/5 pass (node --test, Node v24.20.0)" - "Full suite `node --test tests/**/*.test.mjs`: 47/47 pass (42 pre-existing + 5 new)" - "Mutation probe: + left-pad@1.3.0 (lockfile untouched) → frozen install exits 1 ERR_PNPM_OUTDATED_LOCKFILE, lockfile byte-unchanged" ci_links: - pr: http://gitea:3000/Fabrika/PersonalBlog/pulls/380 - run: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/57 - job: http://gitea:3000/Fabrika/PersonalBlog/actions/runs/57/jobs/69 notes: > On Node v22.23.2 (below the pinned engine floor >=24 <25) the frozen install correctly fails with ERR_PNPM_UNSUPPORTED_ENGINE — the E00-S01-T08 engine restriction is enforced; the acceptance path requires Node 24, matching CI and the docs. No repo files (including the implementer's tests) were modified. ```
Sign in to join this conversation.