Graph task: sdk-main-npm-test-red-blocks-release · state: claimed · priority: 1 · components: [module-sdk]
Agent: janus-sdkfix3
BLOCKED on sdk-ci-runner-shutdown-mid-suite (2026-07-31): npm test cannot reach a verdict in CI (runner shutdown mid-suite, deterministic); the seven tests are fixed but no tag can publish until the gate completes
Found by JANUS 2026-07-30 while landing sdn-sdk-statement-domain-parity. All failures
below reproduce on PRISTINE origin/main (2a0fdc7, before that work) — none are caused by
it, and the parity work's own suites are green.
Why this is P1 rather than housekeeping
.github/workflows/publish.yml runs npm ci && npm test && npm run check:compliance && npm publish on a v* tag. npm test is red on main, so no tag can currently produce a
release. npm is at 0.8.4; main declares 0.8.5, unpublished. Every consumer that pins
the SDK by version is therefore frozen at 0.8.4 — including the JS module-signature
verifier fix that saw-module-signing-enforcement is gated on. The npm-publish-via-Actions
law leaves no CLI escape hatch, and rightly so: the fix is to make main green.
The failures — MEASURED IN CI, not inferred
CI run 30452521214 (main @ 2a0fdc7, before this work) and run 30593468828 (main @
6461ea2, after) fail the SAME seven tests on BOTH node 20 and node 22, and no others.
The parity work added zero. Failing since at least run 30449599431.
browser+wasmedge runtime targets default to a shared single-thread artifact
browser harness executes command-surface invoke envelopes for the shared artifact
browser module harness exposes awaited host dispatch alongside module invoke
browser module harness external arena direct invoke rejects non-shared module memory
inspectModule reports the standalone profile for shared browser/WasmEdge artifacts
checked-in single-file bundle vectors recreate exactly
module flatbuffer stream pump can feed a persistent browser direct-surface module
1–5 and 7 are one cluster: the pthreads artifact guard REJECTS the freshly compiled module
("does not import the wasi thread-spawn host function; does not export
wasi_thread_start"). The guard is doing its job — the emsdk the workflow installs
(./emsdk install latest, unpinned) cannot emit a wasi-threads artifact. An UNPINNED
toolchain under a guard that enforces a pinned contract is the defect; pin emsdk.
6 is separate: the committed single-file bundle vectors no longer reproduce byte-for-byte
from the current writer. A byte-exactness contract — establish which side moved before
regenerating anything.
Locally there is an eighth, CI-green: test/module-sdk.test.js "default standards
dependency exposes the current SCV coverage result contract" (1.101.5 vs
/^1\.101\.[6-9]\d*$/). Stale local node_modules, not a main defect.
Acceptance
npm test green on origin/main, verified by a real CI run; then a v* tag cut so npm
carries the landed work (at minimum the statement-domain verifier). Do not tag before the
run is green — a tag into a known-red gate is not a release, it is noise.
Partial resolution — JANUS 2026-07-30 (landed origin/main c2ea7d1, corrected 0f8c9a9)
The seven are fixed. The release is still blocked, by a different defect — now filed as
sdk-ci-runner-shutdown-mid-suite, which this task is blocked on.
The recorded root cause was wrong, and the correction matters
"An unpinned emsdk install latest under a guard that enforces the pinned wasi-threads
contract" is not what failed. The same six tests fail on a machine that HAS the full
Homebrew wasm32-wasip1-threads toolchain, which rules the toolchain out entirely.
What actually happened: 0bd7688 moved runtimeTargets ["browser","wasmedge"] off the
single-thread default onto the wasi-threads model — deliberately, so that targeting a
browser can never imply emcc. Six tests still compiled a non-threading echo guest through
the inferred default, and a guest that never calls pthread_create links no
wasi.thread-spawn import and exports no wasi_thread_start, so assertPthreadArt _Mirrored from the dev graph (graph/tasks/sdk-main-npm-test-red-blocks-release.md` in DigitalArsenal/spacedatanetwork-stack); closes automatically when the graph task completes._
Graph task:
sdk-main-npm-test-red-blocks-release· state: claimed · priority: 1 · components: [module-sdk]Agent: janus-sdkfix3
Found by JANUS 2026-07-30 while landing
sdn-sdk-statement-domain-parity. All failuresbelow reproduce on PRISTINE
origin/main(2a0fdc7, before that work) — none are caused byit, and the parity work's own suites are green.
Why this is P1 rather than housekeeping
.github/workflows/publish.ymlrunsnpm ci && npm test && npm run check:compliance && npm publishon av*tag.npm testis red on main, so no tag can currently produce arelease. npm is at
0.8.4; main declares0.8.5, unpublished. Every consumer that pinsthe SDK by version is therefore frozen at 0.8.4 — including the JS module-signature
verifier fix that
saw-module-signing-enforcementis gated on. The npm-publish-via-Actionslaw leaves no CLI escape hatch, and rightly so: the fix is to make main green.
The failures — MEASURED IN CI, not inferred
CI run 30452521214 (main @
2a0fdc7, before this work) and run 30593468828 (main @6461ea2, after) fail the SAME seven tests on BOTH node 20 and node 22, and no others.The parity work added zero. Failing since at least run 30449599431.
browser+wasmedge runtime targets default to a shared single-thread artifactbrowser harness executes command-surface invoke envelopes for the shared artifactbrowser module harness exposes awaited host dispatch alongside module invokebrowser module harness external arena direct invoke rejects non-shared module memoryinspectModule reports the standalone profile for shared browser/WasmEdge artifactschecked-in single-file bundle vectors recreate exactlymodule flatbuffer stream pump can feed a persistent browser direct-surface module1–5 and 7 are one cluster: the pthreads artifact guard REJECTS the freshly compiled module
("does not import the wasi
thread-spawnhost function; does not exportwasi_thread_start"). The guard is doing its job — the emsdk the workflow installs(
./emsdk install latest, unpinned) cannot emit a wasi-threads artifact. An UNPINNEDtoolchain under a guard that enforces a pinned contract is the defect; pin emsdk.
6 is separate: the committed single-file bundle vectors no longer reproduce byte-for-byte
from the current writer. A byte-exactness contract — establish which side moved before
regenerating anything.
Locally there is an eighth, CI-green:
test/module-sdk.test.js"default standardsdependency exposes the current SCV coverage result contract" (
1.101.5vs/^1\.101\.[6-9]\d*$/). Stale localnode_modules, not a main defect.Acceptance
npm testgreen onorigin/main, verified by a real CI run; then av*tag cut so npmcarries the landed work (at minimum the statement-domain verifier). Do not tag before the
run is green — a tag into a known-red gate is not a release, it is noise.
Partial resolution — JANUS 2026-07-30 (landed
origin/mainc2ea7d1, corrected 0f8c9a9)The seven are fixed. The release is still blocked, by a different defect — now filed as
sdk-ci-runner-shutdown-mid-suite, which this task is blocked on.The recorded root cause was wrong, and the correction matters
"An unpinned
emsdk install latestunder a guard that enforces the pinned wasi-threadscontract" is not what failed. The same six tests fail on a machine that HAS the full
Homebrew
wasm32-wasip1-threadstoolchain, which rules the toolchain out entirely.What actually happened:
0bd7688movedruntimeTargets ["browser","wasmedge"]off thesingle-thread default onto the wasi-threads model — deliberately, so that targeting a
browser can never imply emcc. Six tests still compiled a non-threading echo guest through
the inferred default, and a guest that never calls
pthread_createlinks nowasi.thread-spawnimport and exports nowasi_thread_start, soassertPthreadArt _Mirrored from the dev graph (graph/tasks/sdk-main-npm-test-red-blocks-release.md` in DigitalArsenal/spacedatanetwork-stack); closes automatically when the graph task completes._