docs(patches): say what pnpm 10.28.2 measurably does on a fumadocs-core bump - #287
Merged
Merged
Conversation
…re bump The "ON A VERSION BUMP" section of the fumadocs-core patch header said a bump drops the pin silently, under a heading that said it fails loudly. Measured with pnpm 10.28.2: regenerating the lockfile after a bump exits 1 with ERR_PNPM_UNUSED_PATCH, and deleting the pin or regenerating with allow-unused-patches are the two paths that end in a silent install. The Locale surface gate fails the build when the defect reaches the built llms output, and was measured red on the pin-deleted tree. The diff hunks are byte-identical. pnpm keys the patch by the sha256 of the whole file, so pnpm-lock.yaml is regenerated by pnpm itself: the only change is the old hash replaced by the new one in its 9 occurrences. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FeA1nwBz1ohH65dvffUGKr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #284
What changed
Only the "ON A VERSION BUMP" section of the header comment in
patches/fumadocs-core@16.8.12.patch, plus thepnpm-lock.yamllines that pnpm 10.28.2 rewrote because of it.The old section contradicted itself. Its heading said "THIS PATCH IS EXPECTED TO FAIL LOUDLY", and its body said "the defect returns silently". The new section says only what #284's table measured with pnpm 10.28.2, on
cb0c146plus #239's one-line version change:--no-frozen-lockfileand--lockfile-onlyboth exit 1 withERR_PNPM_UNUSED_PATCH.--frozen-lockfileon the stale lockfile exits 1 earlier, on mismatched specifiers.allow-unused-patches. The frozen install then accepts that lockfile.Locale surfacestep from ci: fail the build when an llms body carries a numeric character reference or a malformed link target #285 fails the build when eitherllmsoutput carries the defect. It was measured red on the pin-deleted tree. The header claims only that; it does not claim the gate was run on path 2.Left out: the Dependabot-updater inference. Dependabot's updater was not run, so the header does not mention it.
Kept and re-measured: the old section's sentence about 16.15.x reformatting an
ifwas reworded, because this PR measured it. I unpacked both published tarballs in this session.diffshows the only difference indist/mdx-plugins/stringifier.jsis oneifat line 28, which grows from 3 lines to 5.git apply --checkof this patch against 16.15.2 printsHunk #1 succeeded at 68 (offset 2 lines).The header now says the hunk's context sits 2 lines lower there. That replaces the unmeasured "does not necessarily line up" and the inaccurate "two hunks up", since the patch has one hunk. The header makes no claim about how pnpm's own patcher treats that offset, because that was not measured.The diff hunks are byte-identical
Everything from the first
diff --gitline to EOF,origin/main(7004d3d) against this branch (2d9ffcb):diff --gitat byteorigin/main7501cfc05abd506d346be71b686133008a89a2af78d70d33eea33c4e9bfce8d37501cfc05abd506d346be71b686133008a89a2af78d70d33eea33c4e9bfce8d3cmp -llists 0 differing bytes, andcmpexits 0.The lockfile: the hash moved, and pnpm rewrote it
The PM's mechanism assumptions, as measured:
patchedDependencieshash is the sha256 of the whole patch file.sha256sumoforigin/main's file is042796c0…b182ed8d79, exactly the old lockfile hash. The edited file's sha256 isa88318fc…7b625b3dfe57, and that is what pnpm wrote.ERR_PNPM_LOCKFILE_CONFIG_MISMATCH Cannot proceed with the frozen installation. The current "patchedDependencies" configuration doesn't match the value found in the lockfile. I reproduced this before regenerating.pnpm install --lockfile-only(pnpm 10.28.2, exit 0).git diff --numstatreads9 9 pnpm-lock.yaml. The hash appears 9 times: once aspatchedDependencies…hash, and 8 times as thepatch_hash=segment inside the dependency keys offumadocs-coreitself and of its dependentsfumadocs-mdxandfumadocs-ui.origin/main's lockfile and replacing the old hash with the new one (sed s/OLD/NEW/g) gives a file byte-identical to the regenerated one (cmpexit 0). So the hash substitution is the only change: 9 old occurrences before, 9 new ones after, and 0 old ones left.node_moduleswiped in the root andapps/docs(tools/ci-scriptshad none),pnpm install --frozen-lockfileexits 0. The patch still applies, shown the same way as in fix(docs): pin the fumadocs-core peek omission that encodes markdown as entities #281:apps/docs, the virtual-store path isnode_modules/.pnpm/fumadocs-core@16.8.12_patch_hash=a88318fc3b23c44ea3645ae68c43af3a905e0d00d6bc2fcefe3a7b_96ea1a842d0433803cdfc29229a4f307/…/dist/mdx-plugins/stringifier.js. It is the onlyfumadocs-coredirectory in the store.if (handler.peek) wrapped.peek = handler.peek;is at line 81 (count 1). The pristine anchor appears 0 times.Gates run on
2d9ffcb(the head of this PR)Exit codes were captured before any pipe. Each quoted line is the gate's own verdict.
NEXT_PRIVATE_STANDALONE=true pnpm turbo run build --force: exit 0,Tasks: 1 successful, 1 total/Cached: 0 cached, 1 totalnode .github/scripts/check-locale-surface.mjs: exit 0.llms-full.txt: 1 of 1 bodies, 0 numeric references, 661 link targets, 0 malformed.llms.mdx: 79 of 79 bodies, 0 references, 661 targets, 0 malformed. It also prints`fumadocs-core` resolved by `apps/docs`: 16.8.12 · patch pinned to: 16.8.12and✓ every advertised URL has a source file … and neither llms consumer carries a numeric character reference or a malformed link targetpnpm turbo run test --force: exit 0,✓ 7 self-test(s) passednode .github/scripts/check-node-floor.mjs: exit 0,✅ Every declared floor clears what the dependency tree requires, and the declarations agree.(430enginesblocks scanned)grep -naPfor C0 and DEL: 0 matches). Every header line is ASCII and at most 84 columns.Not run locally: Worker packaging, the size weigh-in, and the preview smoke check. CI runs all three.
Not touched
Root
package.json,apps/,content/,.github/, and the patch's diff hunks. #239 was not pushed to, commented on, or merged.🤖 Generated with Claude Code
https://claude.ai/code/session_01FeA1nwBz1ohH65dvffUGKr
Generated by Claude Code
Generated by Claude Code