Skip to content

chore(deps): upgrade @effect/tsgo to 0.46.1 - #16360

Merged
juliusmarminge merged 9 commits into
pingdotgg:mainfrom
esthor:deps/effect-tsgo
Oct 6, 2026
Merged

juliusmarminge merged 9 commits into
pingdotgg:mainfrom
esthor:deps/effect-tsgo

Conversation

@esthor

@esthor esthor commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Problem

@effect/tsgo is pinned at 0.41.0, behind the 0.46.1 that Effect itself uses. 0.41 accepts unknown diagnosticSeverity keys without a warning (Effect-TS/tsgo#747), which is how importFromBarrel silently stopped running after the move to TSGo.

Change

  • @effect/tsgo 0.41.0 → 0.46.1. From 0.46, an unknown rule name fails the typecheck.
  • importFromBarrel comes out of tsconfig.base.json, since TSGo never ported it. chore(lint): import Effect modules from their subpaths #16326 makes the identical change, so whichever merges first, the other still merges cleanly.
  • 0.43 extends nodeBuiltinImport to crypto, timers, and stream. Instead of excepting what it flags, the code moves onto Effect's services:
    • refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto #16377 moved 13 files onto Crypto. @juliusmarminge's commits here move the remaining hashes and UUIDs, including synchronous helpers and tests. Helpers such as checkpointRefForScopeOrdinal, remoteStateKey, and claudePromptUuid become Effects that need Crypto.
    • Desktop's protocol retry and the server's wait for a provider turn to stop use Effect.sleep instead of node:timers/promises.
    • ACP registry archives are checked with a streaming SHA-256 from @noble/hashes. Crypto.digest only hashes a whole buffer, and archives can reach 1 GiB.
  • 26 imports keep Node behind a next-line exception that names what Effect's Crypto lacks: HMAC, signing, key generation or import, or timingSafeEqual. 16 are in tests, and one is a type-only stream import.
  • Every hash keeps its input bytes and output format, so stored and shared names don't change. Among them are checkpoint refs, SSH remote state directories, ACP auth cache files and bindings, credit-redeem request IDs, and MCP server names.
  • Not 0.48:
    • 0.47 adds unstableApiUsage. It warns on every use of effect/http, process, reactivity, and the other unstable modules, about 5,800 times here.
    • 0.48 adds TS2790 errors that look like a packaging regression.

Scope and approval

A toolchain upgrade plus moving Node crypto and timer calls onto Effect services. No behavior change is intended; @noble/hashes is the one new dependency. @juliusmarminge agreed to the upgrade in a private chat and wrote the second half of the migration. I work at CodeRabbit.

Verification

  • CI. Typecheck, lint, build, release smoke, and every test job pass on ce147bf.
  • Hashes. For each converted hash, the old and new code feed the same bytes to SHA-256 or SHA-1 and format the output the same way. The ACP auth-state hash now encodes with Schema's JSON encoder, which produced the same strings as JSON.stringify for plain strings, nested objects and arrays, undefined fields, and non-finite numbers.

0.46.1 is the version Effect itself uses. It reports unknown rule names,
so `importFromBarrel`, which Effect TSGo never ported, goes.

It also extends `nodeBuiltinImport` to `crypto`, `timers`, and `stream`.
Effect's Crypto covers only random values and ids, so each flagged import
keeps Node's API behind a next-line opt-out that names what it needs.
@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Oct 6, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — The dependency upgrade expands into a cross-cutting production migration involving hashing, service wiring, request retries, and timing behavior across multiple subsystems. It also adds numerous static-analysis suppressions and changes authentication-related files, warranting human review.

You can add or adjust custom eligibility rules. Learn more.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Path: .coderabbit.config.ts
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: eb0ee046-0662-4fbe-a854-eb01c6475278
📥 Commits

Reviewing files that changed from the base of the PR and between f0995f9 and 2d8692c.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (3)
  • apps/server/src/orchestration-v2/Adapters/OpenCode2AdapterV2.ts
  • apps/server/src/orchestration-v2/ProviderTurnControlService.ts
  • apps/server/src/preview/PreviewBrowser.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The pull request updates the @effect/tsgo version, removes one Effect language-service diagnostic setting, and adds targeted nodeBuiltinImport suppressions for existing Node built-in imports. The changes do not alter runtime behavior.

Changes

Effect Diagnostic Updates

Layer / File(s) Summary
Diagnostic configuration and import suppressions
pnpm-workspace.yaml, tsconfig.base.json, apps/desktop/src/electron/*, apps/server/src/*, infra/relay/src/*, packages/shared/src/*, packages/ssh/src/*
The @effect/tsgo catalog version changes from 0.41.0 to 0.46.1, and importFromBarrel: "error" is removed from the Effect language-service configuration. Comments suppress nodeBuiltinImport diagnostics for selected Node built-in imports.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Suggested reviewers: juliusmarminge

Merge Risk: ⚪ Minimal · up to 2d869

The PR updates tooling configuration and adds scoped diagnostic suppressions without changing executable behavior. The focused check recognizes the directives and found no errors or warnings, leaving no actionable merge-blocking risk.

Architecture Summary

Architecture risk: 🔵 Low · up to 2d869

The change affects 7 systems.

Changed systems: apps/server, infra, packages/shared, apps/desktop, packages/ssh, pnpm-workspace.yaml, tsconfig.base.json

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — apps/server (service) was modified; 26 changed files map to changed impact.
  • observed — infra (service) was modified; 14 changed files map to changed impact.
  • observed — packages/shared (library) was modified; 3 changed files map to changed impact.
  • observed — apps/desktop (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in apps/desktop/src/electron/ElectronProtocol.ts: Added a diagnostic suppression comment for the Node built-in import, describing its use by fetchWithTransientRetry.
  • observed — Modified behavior in apps/server/src/cloud/CloudLink.ts: Added a one-line diagnostic suppression for the Node.js built-in import rule, with the stated limitation of Effect’s Crypto API.
  • observed — Modified behavior in apps/server/src/cloud/environmentKeys.ts: Added a diagnostic suppression comment for nodeBuiltinImport on the following line.
  • observed — Modified behavior in apps/server/src/scheduledTasks/ScheduledTaskService.webhook.test.ts: Added a next-line Effect diagnostic suppression for the Node built-in import, noting the missing createHmac API in Effect’s Crypto.
🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the @effect/tsgo upgrade, the primary change in the pull request.
Description check ✅ Passed The description covers the problem, changes, scope, approval claim, and verification results. It is mostly complete, but the Scope and approval section does not link to the private discussion or inclu…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. and removed vouch:unvouched PR author is not yet trusted in the VOUCHED list. labels Oct 6, 2026
@juliusmarminge

Copy link
Copy Markdown
Member

@coderabbitai are all of these disable directives really true? effect/Crypto does have hashing. in the cases where we today use sync uuid gen, is there a reason for that or is it just leftovers?

Effect's Crypto has `digest`, `randomBytes`, and UUIDs, so the opt-outs
that said it has no `createHash` or `randomBytes` were wrong. Name only
the APIs it lacks, and where a file needs only hashing or ids, say that
the Node call is synchronous and Effect's is an Effect.
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail
rg -n -C2 'effect:|@effect/tsgo|effect/|nodeBuiltinImport' pnpm-workspace.yaml tsconfig.base.json
rg -n -C1 'effect-diagnostics-next-line.*nodeBuiltinImport' apps infra packages
rg -n -C3 '\b(randomUUID|createHash|createHmac|timingSafeEqual)\s*\(' apps/server/src apps/desktop/src packages/shared/src infra/relay/src
fd -i '^Crypto\.ts$|^package\.json$' | head -60

Length of output: 77999


🏁 Script executed:

#!/bin/bash
set -euo pipefail
python - <<'PY'
import urllib.request,re
url="https://unpkg.com/effect@4.0.1/src/Crypto.ts"
s=urllib.request.urlopen(url).read().decode()
print("SOURCE",url)
lines=s.splitlines()
for i,line in enumerate(lines):
    if re.search(r'^export (const|interface|class|type)|hash:|randomUUIDv4:|randomBytes:|digest:|subtle\.|randomUUID\(',line):
        print("\n".join(f"{j+1}: {lines[j]}" for j in range(max(0,i-3),min(len(lines),i+18))))
PY
for f in apps/server/src/assets/AttachmentUpload.ts apps/server/src/cli/app.ts apps/server/src/preview/Manager.ts apps/server/src/project/ProjectSetupScriptRunner.ts apps/server/src/vcs/GitVcsDriver.ts apps/server/src/mcp/McpHttpServer.ts apps/desktop/src/preview/Manager.ts; do
  echo "=== $f ==="
  ast-grep outline "$f" --items all --type function --view compact | head -90
done
rg -n -C12 'NodeCrypto\.randomUUID\(' apps/server/src/assets/AttachmentUpload.ts apps/server/src/cli/app.ts apps/server/src/preview/Manager.ts apps/server/src/project/ProjectSetupScriptRunner.ts apps/server/src/vcs/GitVcsDriver.ts apps/server/src/mcp/McpHttpServer.ts apps/desktop/src/preview/Manager.ts
rg -n -C3 'Crypto\.(digest|randomUUIDv4|randomBytes)|from "effect/Crypto"' apps infra packages | head -180

Length of output: 2573


🏁 Script executed:

#!/bin/bash
python - <<'PY'
import urllib.request,json,tarfile,io,re
meta=json.load(urllib.request.urlopen("https://registry.npmjs.org/effect/4.0.1", timeout=30))
t=tarfile.open(fileobj=io.BytesIO(urllib.request.urlopen(meta["dist"]["tarball"],timeout=30).read()),mode="r:gz")
for name in ["package/src/Crypto.ts","package/dist/Crypto.d.ts"]:
    try: s=t.extractfile(name).read().decode()
    except KeyError: continue
    print("SOURCE",name)
    lines=s.splitlines()
    for i,line in enumerate(lines):
        if re.search(r'^export (const|interface|class|type)|hash:|randomUUIDv4:|randomBytes:|digest:|subtle\.|randomUUID\(',line):
            print("\n".join(f"{j+1}: {lines[j]}" for j in range(max(0,i-2),min(len(lines),i+23))))
    break
PY
for f in apps/server/src/assets/AttachmentUpload.ts apps/server/src/cli/app.ts apps/server/src/preview/Manager.ts apps/server/src/project/ProjectSetupScriptRunner.ts apps/server/src/vcs/GitVcsDriver.ts apps/server/src/mcp/McpHttpServer.ts apps/desktop/src/preview/Manager.ts; do
  echo "=== $f ==="
  ast-grep outline "$f" --items all --type function | head -65
done
sed -n '140,205p' apps/server/src/assets/AttachmentUpload.ts
sed -n '175,225p' apps/server/src/cli/app.ts
sed -n '325,382p' apps/server/src/project/ProjectSetupScriptRunner.ts
sed -n '790,825p' apps/server/src/vcs/GitVcsDriver.ts
sed -n '315,345p' apps/server/src/mcp/McpHttpServer.ts
sed -n '1640,1685p' apps/desktop/src/preview/Manager.ts
sed -n '4175,4205p' apps/desktop/src/preview/Manager.ts
rg -n -C3 'Crypto\.(digest|randomUUIDv4|randomBytes)|from "effect/Crypto"' apps infra packages | head -180

Length of output: 44002


@juliusmarminge No. Some comments name a missing Node API, but imply that Effect lacks the capability. You are right about hashing. Thanks for the clarification.

I checked the published effect@4.0.1 source, which matches this repository’s catalog version.

Hashing and other crypto operations

Suppression reason Assessment
“Crypto has no createHash” Literally true, but misleading. Crypto.digest supports SHA-1, SHA-256, SHA-384, and SHA-512. All algorithms in the inspected hash calls are supported.
“Crypto has no randomBytes” Incorrect. The Crypto service has randomBytes(size). This affects apps/server/src/provider/opencode2/OpenCode2Client.live.test.ts.
No createHmac or timingSafeEqual Valid API gap in this version. digest does not replace HMAC or constant-time comparison.
No key-pair generation, key-object conversion, sign, or verify Valid API gap in this version.
Node stream type import and timers in plain async code Separate interoperability reasons. These do not depend on Crypto support.

Some hash-only imports are clear migration candidates. For example:

  • apps/server/src/provider/ProviderCredentialStore.ts
  • apps/server/src/device/SshDeviceHost.ts
  • apps/server/src/pullRequest/GitHubPullRequestCli.ts

Their hash calls already run inside Effect generators.

Other hash calls belong to synchronous helpers, such as checkpointRefFor’s surrounding checkpoint-reference logic and claudePromptUuid. Replacing those calls requires changing the helper contract or moving digest computation into an Effect caller. That is a migration cost, not missing hashing support.

Streaming hashes need a separate assessment. Crypto.digest accepts the complete input; it does not expose Node’s incremental Hash.update API. Replacing a streaming hash with a buffered digest can change memory use.

Synchronous UUID generation

I found no demonstrated requirement for synchronous UUID generation in the eight UUID-only files. Their UUID calls are already inside Effect execution:

File UUID purpose
apps/server/src/assets/AttachmentUpload.ts Temporary upload filename
apps/server/src/cli/app.ts Activation request ID
apps/server/src/preview/Manager.ts Server epoch
apps/server/src/project/ProjectSetupScriptRunner.ts Completion token
apps/server/src/vcs/GitVcsDriver.ts Temporary Git index filename
apps/server/src/mcp/McpHttpServer.ts Screenshot filename
apps/server/src/ws.ts Command ID
apps/desktop/src/preview/Manager.ts Evaluation groups and automation keys

The desktop calls include Effect.suspend and synchronous callbacks, but UUID generation can move into the surrounding Effect before those callbacks.

These look like migration leftovers rather than required synchronous boundaries. I did not check their history, so I cannot establish the original intent.

There is a real type-level cost: crypto.randomUUIDv4 declares PlatformError, and callers need the Crypto.Crypto service. However, that does not require exposing a new error in every public service contract. Callers can map the error into an existing domain error, or deliberately convert it to a defect.

My recommendation is to migrate the UUID-only and Effect-native hash-only cases. Keep narrow suppressions for unsupported operations, synchronous contracts retained intentionally, and incremental hashing. The comments should state those actual constraints instead of saying that Effect lacks hashing.


✏️ Learnings added
Learnt from: juliusmarminge
URL: https://github.com/pingdotgg/t3code/pull/16360

Timestamp: 2026-10-06T05:12:08.693Z
Learning: In pingdotgg/t3code with effect4.0.1, effect/Crypto provides service methods digest (SHA-1, SHA-256, SHA-384, SHA-512), randomBytes, and randomUUIDv4. A nodeBuiltinImport suppression stating that Crypto lacks createHash must not be interpreted as lack of hashing support. Assess synchronous helper contracts and incremental hashing separately from capability gaps. This version's Crypto service does not expose HMAC, timingSafeEqual, key-pair generation, key-object conversion, signing, or verification.

Note: Learnings are effective only in the context of similar code segments. To apply general coding guidelines, please configure review instructions. You can manage existing learnings in the app.

You are interacting with an AI system.

@esthor

esthor commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

You're right, I missed digest and randomBytes. Fixed in ee0371e: the opt-outs now name only what Effect's Crypto lacks (HMAC, signing, keys, timingSafeEqual). Where a file only hashes or makes ids, they say the Node call is synchronous and Effect's is an Effect.

On sync UUIDs: mostly leftovers. Of the 13 randomUUID calls, 10 already run inside Effect code (9 in generators, 1 in Effect.suspend), and 2 are in plain sync functions. createHash is similar: 9 of 31 calls are in generators, 21 in sync helpers, and 1 at module top level.

Moving the Effect-context ones to Crypto adds a Crypto dependency and a PlatformError to map in each service, so I'd do it as its own PR after this one.

@esthor

esthor commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

The move is up in #16377. Two corrections to my reply above:

  • There are 12 randomUUID calls, not 13. The two I called plain sync functions also run inside Effect code: one is a thunk passed to attempt, and the other builds an Effect. So all of them are leftovers. refactor: Effect code gets UUIDs and SHA-256 from Effect's Crypto #16377 moves 11. The twelfth is in AcpRegistrySupport.ts, which stays on Node because it hashes downloads as they stream.
  • No service gains a PlatformError. Node's throws already surfaced as defects, and Effect.orDie keeps that behavior.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Autopilot could not be updated. Open Coding to check access and billing.

# Conflicts:
#	apps/desktop/src/preview/Manager.ts
#	apps/server/src/assets/AttachmentUpload.ts
#	apps/server/src/assets/NativeAppIconResolver.ts
#	apps/server/src/cli/app.ts
#	apps/server/src/device/SshDeviceHost.ts
#	apps/server/src/mcp/McpHttpServer.ts
#	apps/server/src/preview/Manager.ts
#	apps/server/src/project/ProjectSetupScriptRunner.ts
#	apps/server/src/provider/ProviderCredentialStore.ts
#	apps/server/src/provider/openCodeUsageLimits.ts
#	apps/server/src/pullRequest/GitHubPullRequestCli.ts
#	apps/server/src/vcs/GitVcsDriver.ts
#	apps/server/src/ws.ts
@github-actions github-actions Bot added size:M 30-99 changed lines (additions + deletions). and removed size:L 100-499 changed lines (additions + deletions). labels Oct 6, 2026
juliusmarminge and others added 3 commits October 6, 2026 08:46
…s from main

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Replaces the nodeBuiltinImport opt-outs for synchronous createHash,
randomUUID, randomBytes and Node timers with Effect's Crypto service and
Effect.sleep/Schedule, threading Crypto through callers. Persisted
hashes, refs and ids are unchanged; tests pin the previous outputs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added size:XL 500-999 changed lines (additions + deletions). and removed size:M 30-99 changed lines (additions + deletions). labels Oct 6, 2026
Comment thread apps/server/src/provider/acp/AcpRegistrySupport.ts Outdated
juliusmarminge and others added 2 commits October 6, 2026 10:30
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Reading the downloaded archive back to verify its SHA-256 loaded up to
1 GiB into memory. Hash each chunk as it streams with @noble/hashes,
since Effect's Crypto only digests a whole buffer.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@juliusmarminge
juliusmarminge merged commit 78552a8 into pingdotgg:main Oct 6, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:XL 500-999 changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants