fix(zdeploy): verify against the committed build stamp, and read 5-segment versions (#37)

Deploy verification expected buildNumber + 1, which was only correct while
a prebuild hook self-incremented the stamp during the image build. That hook
is gone (it produced versions matching no commit and left every build with a
dirty tree), so the check waited out its timeout and warned on every deploy
even when the deploy had succeeded.

Both verifier call sites now expect the committed label, and
Get-LabelFromBuildJsonObj understands the 5-segment scheme
v{major}.{rc}.{beta}.{alpha}.{build} while still reading the legacy
{productVersion, buildNumber} stamp for projects that haven't migrated.

Verified: both files parse; label fn returns v0.0.0.1.8 (5-segment) and
v1.0.0.70 (legacy).

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
kellymichels 2026-08-05 19:22:34 -05:00 committed by GitHub
parent 0ddffc1020
commit a8689732ba
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 14 additions and 5 deletions

View File

@ -185,6 +185,12 @@ function Read-JsonBuildVersion {
function Get-LabelFromBuildJsonObj { function Get-LabelFromBuildJsonObj {
param($obj) param($obj)
if (-not $obj) { return $null } if (-not $obj) { return $null }
# Five-segment scheme: v{major}.{rc}.{beta}.{alpha}.{build}
if ($null -ne $obj.build -or $null -ne $obj.alpha) {
$alpha = if ($null -ne $obj.alpha) { [int]$obj.alpha } else { 1 }
return "v$([int]$obj.major).$([int]$obj.rc).$([int]$obj.beta).$alpha.$([int]$obj.build)"
}
# Legacy two-part stamp (projects not yet migrated): v{productVersion}.{buildNumber}
return "v$([string]$obj.productVersion).$([int]$obj.buildNumber)" return "v$([string]$obj.productVersion).$([int]$obj.buildNumber)"
} }

View File

@ -178,9 +178,12 @@ function Wait-VerifyStaticBuild {
Write-Host "`n--- [$Key version] SKIPPED (no local build-version.json - see 'Enabling deploy verification' in README) ---" -ForegroundColor DarkYellow Write-Host "`n--- [$Key version] SKIPPED (no local build-version.json - see 'Enabling deploy verification' in README) ---" -ForegroundColor DarkYellow
return return
} }
$expBn = [int]$PreZipBuildState.buildNumber + 1 # Expect the COMMITTED stamp, not +1: builds no longer self-bump (a
$pv = [string]$PreZipBuildState.productVersion # prebuild hook incremented inside the image, so the served version
$expectedLabel = "v$pv.$expBn" # matched no commit and every build dirtied the tree). The counter now
# advances deliberately — one version bump per merged PR — so "is the
# build I just packed live?" means an exact match.
$expectedLabel = Get-LabelFromBuildJsonObj $PreZipBuildState
Write-Host "`n--- [$Key] Live build verification (expect $expectedLabel) ---" -ForegroundColor Cyan Write-Host "`n--- [$Key] Live build verification (expect $expectedLabel) ---" -ForegroundColor Cyan
$containerName = $Proj.remote.containerName $containerName = $Proj.remote.containerName
$deadline = (Get-Date).AddSeconds(45) $deadline = (Get-Date).AddSeconds(45)
@ -536,8 +539,8 @@ function Invoke-NextDeploy {
} }
} }
if ($preZipBuild) { if ($preZipBuild) {
$expBn = [int]$preZipBuild.buildNumber + 1 # Committed stamp, not +1 — see the note in Wait-VerifyStaticBuild.
$expectedLabel = "v$([string]$preZipBuild.productVersion).$expBn" $expectedLabel = Get-LabelFromBuildJsonObj $preZipBuild
Wait-VerifyApiBuild -Key $Key -Proj $Proj -ExpectedLabel $expectedLabel -TimeoutSec 60 | Out-Null Wait-VerifyApiBuild -Key $Key -Proj $Proj -ExpectedLabel $expectedLabel -TimeoutSec 60 | Out-Null
} else { } else {
Write-Host " (No public/build-version.json - version verification skipped. See 'Enabling deploy verification' in README.)" -ForegroundColor DarkYellow Write-Host " (No public/build-version.json - version verification skipped. See 'Enabling deploy verification' in README.)" -ForegroundColor DarkYellow