Skip to content

fix(pit): vendor the namespace rules again — main is red - #163

Merged
ralyodio merged 1 commit into
mainfrom
fix/pwa-name-vendored
Jul 31, 2026
Merged

fix(pit): vendor the namespace rules again — main is red#163
ralyodio merged 1 commit into
mainfrom
fix/pwa-name-vendored

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

#161 broke main. Three test files fail at import with ERR_MODULE_NOT_FOUND:

Cannot find package '@moshcoder/moshpit-name'
  imported from apps/pwa/src/lib/moshpit-name.mjs

What I got wrong

apps/pwa is not part of a pnpm workspace and there's no workspaces field, so the repo-root pnpm install --frozen-lockfile that CI runs never reaches it. Its dependencies are simply absent in CI — which is why 116 of its tests have always skipped.

My claim in #161 that this was "the one consumer that does npm install" was wrong. Nothing installs them in CI.

And the failure mode got worse. Those tests used to skip when a dependency was missing. A re-export at the top of a module every one of them imports fails at load instead — so the pure tests, which need nothing, went down with the ones that need a database.

The fix

The vendored copy comes back, with the same treatment src/dns.mjs got in #162: a dev-only dependency plus a drift test comparing behaviour, not bytes.

Covers parsing across the whole hostname space, the reserved list, prices and limits, pasted lists with per-line settings, and resolution precedence.

Verified both ways this time

  • Skips cleanly with no dev dependencies — which is what CI has
  • Fails on real drift — changing ENDING_PRICE_USD in the copy alone turns it red
  • Full suite with apps/pwa/node_modules removed, i.e. CI exactly: 484 pass, 0 fail, 122 skipped

That last check is the one I should have run before #161.

🤖 Generated with Claude Code

#161 replaced apps/pwa/src/lib/moshpit-name.mjs with a re-export of
@moshcoder/moshpit-name. That broke main: three test files now fail at import
with ERR_MODULE_NOT_FOUND.

I had it wrong. apps/pwa is not part of a pnpm workspace and has no workspaces
field, so the repo-root `pnpm install --frozen-lockfile` that CI runs never
reaches it — its dependencies are simply absent there, which is why 116 of its
tests have always skipped. The claim in #161 that this was "the one consumer
that does npm install" was not true; nothing installs them in CI.

Worse, the failure mode changed. Those tests used to skip when a dependency was
missing. A re-export at the top of a module every one of them imports fails at
load instead, so the pure tests — which need nothing — went down with the ones
that need a database.

So the vendored copy comes back, and gets the same treatment as src/dns.mjs in
#162: a dev-only dependency and a drift test that compares behaviour rather
than bytes. Parsing across the whole hostname space, the reserved list, prices
and limits, pasted lists with their per-line settings, and resolution
precedence.

Verified both ways this time. It skips cleanly with no dev dependencies, which
is what CI has. It fails when ENDING_PRICE_USD is changed in the copy alone.
And the full suite with apps/pwa/node_modules removed — CI, exactly — is 484
pass, 0 fail, 122 skipped.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 06bd138 into main Jul 31, 2026
3 checks passed
@ralyodio
ralyodio deleted the fix/pwa-name-vendored branch July 31, 2026 20:03
@ralyodio ralyodio mentioned this pull request Aug 1, 2026
ralyodio added a commit that referenced this pull request Aug 1, 2026
install.sh resolves releases/latest, so the sixteen commits merged since
v0.13.3 have been sitting on main unreachable — including a fix for a page
that locks browsers up.

The headline is the pit. /pit rendered every ending an account held and a form
per name under each, with no bound on either: at 50 endings x 100 names that
was 3.1 MiB of HTML and 36,082 DOM elements, and it managed to jam a browser
with no script on the page at all (#167). It now draws a window and says what
it is not drawing — 173 KiB, 1,926 elements — with a filter box over the top
that takes `eggs` as a substring and `def*` as a glob, debounced against the
API (#168).

The namespace also stopped being the one part of the product a script could
not touch: /api/moshpit/* now accepts the same API key /api/me and
/api/sessions already did (#169), and /pit/dns finally documents the
TronBrowser route for machines whose DNS is not theirs to change (#165).

  moshcode: foreign keys are enforced, and the licence package.json
  claims actually ships (#154)
  cli: help aliases exit 0 (#157), invalid integration commands fail (#160),
  `--` is honoured (#159), a BOM before a shebang no longer breaks (#158)
  skills: engines with no skills primitive are reported, not dropped (#166);
  `--name` requires a value (#156)
  mcp: an unsupported flag is rejected rather than registered as the server
  name (#164)
  pit: the namespace rules are vendored again with a drift test holding them
  to the published package (#161, #162, #163)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant