From 1ba237a63465051968e138dbf0f468541078fef3 Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 13 Sep 2026 02:55:24 +0200 Subject: [PATCH] Stage the sdk from its own checkout, not from a symlink that may not be one MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Both image scripts copied the runtime's installed tree and relied on the sdk inside it being a link into the sibling repository. That is true only where somebody linked them by hand, and false as soon as the dependencies are installed the ordinary way — which fetches the sdk as sources with nothing compiled. The image still built, and every entry point in it pointed at nothing. --- scripts/build-module-runtime.sh | 10 ++++++++++ scripts/build-runtime-image.sh | 12 +++++++++++- 2 files changed, 21 insertions(+), 1 deletion(-) diff --git a/scripts/build-module-runtime.sh b/scripts/build-module-runtime.sh index baa92c3..cff3e8f 100755 --- a/scripts/build-module-runtime.sh +++ b/scripts/build-module-runtime.sh @@ -38,6 +38,16 @@ TSC="$MESH_SDK/node_modules/.bin/tsc"; ( cd "$MOD" && "$TSC" "${SRCS[@]}" --modu STAGE="$(mktemp -d)"; trap 'rm -rf "$STAGE"' EXIT cp -r "$MESH_TOOLS/dist" "$STAGE/dist" cp -rL "$MESH_TOOLS/node_modules" "$STAGE/node_modules" +# And the sdk, from the sibling this script just built, whatever form the installed tree holds it +# in. It used to be relied on being a symlink into that sibling, which `-L` above materialised — +# true only on a workstation where somebody had linked them, and false the moment the runtime's +# dependencies are installed the ordinary way, which now fetches the sdk as sources with nothing +# compiled in it. The image built then looked fine and every entry point inside it pointed at +# nothing. +rm -rf "$STAGE/node_modules/@novox/mesh-sdk" +mkdir -p "$STAGE/node_modules/@novox" +cp -rL "$MESH_SDK" "$STAGE/node_modules/@novox/mesh-sdk" +rm -rf "$STAGE/node_modules/@novox/mesh-sdk/node_modules" mkdir -p "$STAGE/modules/$MODULE"; cp -r "$MOD/dist" "$STAGE/modules/$MODULE/dist" cp "$MESH_TOOLS/package.json" "$STAGE/package.json" diff --git a/scripts/build-runtime-image.sh b/scripts/build-runtime-image.sh index 41cabec..e6ca133 100755 --- a/scripts/build-runtime-image.sh +++ b/scripts/build-runtime-image.sh @@ -36,7 +36,17 @@ echo " module $AUDIT" STAGE="$(mktemp -d)" trap 'rm -rf "$STAGE"' EXIT cp -r "$MESH_TOOLS/dist" "$STAGE/dist" -cp -rL "$MESH_TOOLS/node_modules" "$STAGE/node_modules" # -L materialises the @novox/mesh-sdk symlink +cp -rL "$MESH_TOOLS/node_modules" "$STAGE/node_modules" +# And the sdk, from the sibling this script just built, whatever form the installed tree holds it +# in. It used to be relied on being a symlink into that sibling, which `-L` above materialised — +# true only on a workstation where somebody had linked them, and false the moment the runtime's +# dependencies are installed the ordinary way, which now fetches the sdk as sources with nothing +# compiled in it. The image built then looked fine and every entry point inside it pointed at +# nothing. +rm -rf "$STAGE/node_modules/@novox/mesh-sdk" +mkdir -p "$STAGE/node_modules/@novox" +cp -rL "$MESH_SDK" "$STAGE/node_modules/@novox/mesh-sdk" +rm -rf "$STAGE/node_modules/@novox/mesh-sdk/node_modules" # -L materialises the @novox/mesh-sdk symlink mkdir -p "$STAGE/modules/audit-logger" cp -r "$AUDIT/dist" "$STAGE/modules/audit-logger/dist" cp "$MESH_TOOLS/package.json" "$STAGE/package.json"