F1 (demonstrated defect): surface 2 was a regex over raw YAML text, so a
commented-out ci.yml invocation still counted as enumerated — #1017's own
failure mode reproduced inside the fix, in the most common disable path
there is. Comment lines are now skipped before matching; needles n8/c4
pin both polarities (a comment is not enumeration; a comment naming an
absent path raises no false stale-enumeration). The residual trailing-
comment limit is documented where the grep lives.
F2 (structural): the guard was link [0] of the six-hop pnpm chain it
guards, so severing that chain silenced guard and guarded together.
ci.yml now invokes it directly from the sanitization step too — reachable
from both surfaces it audits, so either path alone keeps one instrument
running.
F3 (vocabulary): failure line and header said 'reachable'; F1/F2 prove
the guard measures NAMING. It now says 'enumerated' everywhere, matching
the success line.
Needles: 14 passed / 0 failed. Real tree: population 44, enumerated 25,
excluded (signed) 19, surfaces 38, unchanged — F2's line adds redundancy,
not membership. F1 demo replayed against the fix: commenting out
test-install-migration.sh now fails loud (UNENUMERATED, rc=1).
Written-by: pepper (sb-it-1-dt)
Co-Authored-By: Claude Fable 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01NsKce8iZuSuRnu3gVMCBKB
Publish pipeline:
- Add publish-npm step to .woodpecker/publish.yml — publishes all
@mosaic/* packages to Gitea npm registry on main push/tag
- Requires gitea_npm_token Woodpecker secret (package:write scope)
- publish-npm runs after build, parallel with Docker image builds
- pnpm publish resolves workspace:* to concrete versions automatically
Package configuration:
- All 20 packages versioned at 0.0.1-alpha.1
- publishConfig added to all packages (Gitea registry, public access)
- files field added to all packages (ship only dist/)
- @mosaic/forge includes pipeline/ assets in published package
Meta package (@mosaic/mosaic):
- Now depends on @mosaic/forge, @mosaic/macp, @mosaic/prdy,
@mosaic/quality-rails, @mosaic/types
- npm install @mosaic/mosaic pulls in the standalone framework
Build fixes:
- Fix forge and macp tsconfig rootDir: '.' -> 'src' so dist/index.js
resolves correctly (was dist/src/index.js)
- Exclude __tests__ and vitest.config from build includes
- Clean stale build artifacts from old rootDir config
Required Woodpecker secret:
woodpecker secret add mosaic/mosaic-stack \
--name gitea_npm_token --value '<token>' \
--event push,manual,tag
Each step was re-running pnpm install independently, and all quality
steps (typecheck, lint, format, test) ran in parallel. On merge commits
with more accumulated code this pushed the CI runner over its memory
limit (exit code 254 = OOM kill).
Fix:
- install once, share node_modules via Woodpecker workspace volume
- sequential execution: install → typecheck → lint → format → test → build
- corepack enable in each step (fresh container) but no redundant install