v0.7.7 — two releases shipped to a browser that never received them

buildStamp()'s no-git fallback was the literal "nogit", and the .s9pk
Dockerfile copies the tree in without .git — so git rev-parse fails on
every packaged build. That string is also the cache-bust key every
module URL carries, so v0.7.4, v0.7.5 and v0.7.6 all published
./web/main.js?v=nogit, byte-identical, and returning browsers refetched
nothing. v0.7.5's setup screen and v0.7.6's door fix were both correct
and neither arrived.

The fallback is now the package version plus the build timestamp, always
distinct. And serveStatic sent no Cache-Control at all, which is the
other half — a cached play.html pins a player to the whole build it
names. A request carrying ?v= is now immutable for a year; everything
else is no-cache. ?v= rather than "not HTML" because build-web.ts tags
the modules and nothing else.

Neither half is sufficient alone.

864 tests pass, two new.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AdG46Ja2PEDBkpqiDazMoX
This commit is contained in:
Jesse.Markowitz
2026-08-29 22:23:09 -04:00
co-authored by Claude Sonnet 5
parent b4f09f05cb
commit af68aac78d
6 changed files with 129 additions and 10 deletions
+30 -4
View File
@@ -101,7 +101,13 @@ function sendJson(res: ServerResponse, status: number, body: unknown): void {
res.end(text);
}
async function serveStatic(distDir: string, urlPath: string, res: ServerResponse): Promise<void> {
async function serveStatic(
distDir: string,
urlPath: string,
res: ServerResponse,
/** The request's `?v=` build tag, when it has one — see the `Cache-Control` note below. */
buildTagged = false,
): Promise<void> {
const rel = urlPath === '/' ? '/index.html' : urlPath;
// `normalize` collapses `..`, and the join is then checked to still be inside `distDir` — a request
// for `/../../etc/passwd` must not escape the one directory this is allowed to read from.
@@ -113,7 +119,27 @@ async function serveStatic(distDir: string, urlPath: string, res: ServerResponse
try {
const info = await stat(full);
if (!info.isFile()) throw new Error('not a file');
res.writeHead(200, { 'Content-Type': MIME[extname(full)] ?? 'application/octet-stream', 'Content-Length': info.size });
/**
* ONLY A URL CARRYING A BUILD TAG MAY BE CACHED, AND NOTHING ELSE MAY BE.
*
* Nothing here sent a `Cache-Control` at all before, so a browser applied its own heuristic to
* the pages as much as the modules. The pages are the one thing that CANNOT be versioned in
* their own URL — a player types the address or follows a bookmark — so a cached `play.html`
* pins that player to the entire build it names, including every `?v=` tag inside it. That is
* half of why v0.7.5 and v0.7.6 did not reach the browser that asked for them; `build-web.ts`
* publishing `?v=nogit` on every packaged release was the other half, and neither is enough on
* its own.
*
* `?v=` is the exact condition rather than "not HTML": `build-web.ts` tags the modules and the
* script tags that load them, and tags NOTHING else. An untagged URL — an image, the replay
* manifest — has no way to announce a change, so a year of `immutable` on one would outlive
* several releases of whatever it holds.
*/
res.writeHead(200, {
'Content-Type': MIME[extname(full)] ?? 'application/octet-stream',
'Content-Length': info.size,
'Cache-Control': buildTagged ? 'public, max-age=31536000, immutable' : 'no-cache',
});
createReadStream(full).pipe(res);
} catch {
res.writeHead(404, { 'Content-Type': 'text/plain' });
@@ -281,7 +307,7 @@ export function startServer(opts: ServerOptions): void {
// Unset means the routes are not here — indistinguishable from any other unknown path, so
// nothing advertises an administrative surface to someone probing for one.
if (!opts.adminSecret) {
await serveStatic(opts.distDir, url.pathname, res);
await serveStatic(opts.distDir, url.pathname, res, url.searchParams.has('v'));
return;
}
if (req.headers['x-admin-secret'] !== opts.adminSecret) {
@@ -700,7 +726,7 @@ export function startServer(opts: ServerOptions): void {
return;
}
await serveStatic(opts.distDir, url.pathname, res);
await serveStatic(opts.distDir, url.pathname, res, url.searchParams.has('v'));
})().catch((err: unknown) => {
sendJson(res, 500, { error: err instanceof Error ? err.message : 'internal error' });
});