From 9e06ffaf3866ce93643469c8546989aef9a47476 Mon Sep 17 00:00:00 2001 From: "upstash-tag[bot]" <313023939+upstash-tag[bot]@users.noreply.github.com> Date: Wed, 30 Sep 2026 10:58:10 +0000 Subject: [PATCH] fix(eve-extension): rebuild against eve 0.68.0, raise peer floor to >=0.68.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit packages/eve stays on eve 0.65.0 — its Upstash Box sandbox code still uses eve's removed MutableNetworkSandboxSession type and needs a source port (tracked separately), not a mechanical bump. --- .changeset/eve-extension-eve-0-68.md | 19 +++++++++ CLAUDE.md | 36 ++++++++++++---- examples/eve-extension-demo/package.json | 2 +- packages/eve-extension/AGENTS.md | 2 +- packages/eve-extension/README.md | 2 +- packages/eve-extension/package.json | 4 +- pnpm-lock.yaml | 52 +++++++++++++++++++++--- 7 files changed, 99 insertions(+), 18 deletions(-) create mode 100644 .changeset/eve-extension-eve-0-68.md diff --git a/.changeset/eve-extension-eve-0-68.md b/.changeset/eve-extension-eve-0-68.md new file mode 100644 index 0000000..ab816e7 --- /dev/null +++ b/.changeset/eve-extension-eve-0-68.md @@ -0,0 +1,19 @@ +--- +"@upstash/agentkit-eve-extension": minor +--- + +fix!: rebuild the extension against `eve` 0.68.0 and raise the `eve` peer floor to `>=0.68.0` + +The dist is now built with **eve 0.68.0** and its `dist/extension/_manifest.json` stamps tool +contract **59**, dynamicTool **56** and hook **29** (previously 55 / 52 / 25, built with 0.65.0). +0.68.0 is the first eve that accepts all three: 0.67.0–0.67.2 accept dynamicTool 56 but not tool 59 or +hook 29, and 0.65.0–0.66.3 accept none of them. The peer range therefore moves `">=0.65.0"` → +**`">=0.68.0"`**, so an eve that cannot run this dist is rejected at install (`ERESOLVE`) instead of +installing cleanly and then failing at `eve build` with +`Selected module binding "extensions/agentkit.ts" has no compile or runtime usage.` + +**Upgrading:** move your app to `eve@^0.68.0` together with this release. If you must stay on +eve 0.65–0.67, stay on `@upstash/agentkit-eve-extension@0.13.0`, which also keeps working on eve 0.68. + +**No behaviour or API changed**: the same extension source recompiled against a newer eve. The mount, +its options, every contributed tool and hook, and everything written to Redis are unchanged. diff --git a/CLAUDE.md b/CLAUDE.md index 78913f7..d6e166e 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -121,9 +121,12 @@ and `eve-extension-demo` (a minimal eve scaffold that mounts the extension). npm/yarn hoisted layouts — was fixed upstream in eve 0.25.3; no workaround needed on ≥0.25.3.) **Consumer eve version:** `eve extension build` stamps the manifest's `requires` with the building eve's *current* contribution-format versions, and a consumer rejects any version not in its own - supported list — the current dist, built with **eve 0.65.0**, stamps formatVersion 2; extension 1 / - **tool 55** / **dynamicTool 52** / **hook 25** / instructions 2 / config 1, which needs consumers on - **eve ≥0.65.0** — 0.65.0 is the first release accepting tool 55 (the 0.64.1 build stamped tool 54), because eve now + supported list — the current dist, built with **eve 0.68.0**, stamps formatVersion 2; extension 1 / + **tool 59** / **dynamicTool 56** / **hook 29** / instructions 2 / config 1, which needs consumers on + **eve ≥0.68.0** — 0.68.0 is the first release accepting tool 59 and hook 29 (0.67.0–0.67.2 accept + dynamicTool 56 but neither of the others; 0.65.0–0.66.3 accept none of the three). The previous dist, + built with 0.65.0, stamped tool 55 / dynamicTool 52 / hook 25 (floor 0.65.0; the 0.64.1 build stamped + tool 54), because eve now **drops** mid-range contracts rather than only adding new ones (0.64.0's supported `tool` list is [1–13, 29–32, 34, 35, 54], its `dynamicTool` list [1–20, 22, 31–33, 52] and its `hook` list [10–15, 17–23, 25] — 0.64.0 dropped **tool 53, dynamicTool 51 AND hook 24 in one release**, which is @@ -151,7 +154,7 @@ and `eve-extension-demo` (a minimal eve scaffold that mounts the extension). release's worth of headroom. Since ~0.50 eve also **drops** contracts out of the middle of its supported range, so a *newer* eve is not automatically compatible either: the floor has repeatedly landed on the pinned version itself, with **no back-compat window at all**. - The `eve` peer is **`">=0.65.0"`, not `"*"`** — issue #22 proved the wildcard is a trap: eve + The `eve` peer is **`">=0.68.0"`, not `"*"`** — issue #22 proved the wildcard is a trap: eve 0.33 dropped hook contracts ≤9 *nine hours* after 0.32 shipped, so a wildcard install succeeds and then fails at `eve build` with a manifest error. The manifest is still the real compatibility tie; the peer floor is the install-time guard. **On every eve devDep bump: rebuild, read the new @@ -474,7 +477,7 @@ and `eve-extension-demo` (a minimal eve scaffold that mounts the extension). `new Ratelimit()`. ## AI SDK version strategy — IMPORTANT -- **AI SDK v7 stable everywhere.** Every package + demo pins `ai` to exactly **`7.0.107`**. `eve` (0.63.0 through 0.65.0 alike) +- **AI SDK v7 stable everywhere.** Every package + demo pins `ai` to exactly **`7.0.107`**. `eve` (0.63.0 through 0.68.0 alike) declares `ai` as a **peer** (`^7.0.105` — it sat at `^7.0.82` from 0.47.6 through 0.52.3, moved to `^7.0.93` somewhere in 0.53.0 → 0.55.0 and to `^7.0.105` by 0.61.0, so the 0.52.3 → 0.55.0 bump forced the repo-wide pin `7.0.87` → `7.0.101` and the 0.55.0 → 0.63.0 bump `7.0.101` → `7.0.107`), so the @@ -617,6 +620,9 @@ and `eve-extension-demo` (a minimal eve scaffold that mounts the extension). distinguishing detail in a failing eval gate: `observed calls: {}` means the tool **mounted and ran** (and Redis failed underneath), whereas `observed tools: []` means the tool **never mounted** — only the latter is a real code problem. + **Idle control settles it:** provision one more DB, run nothing against it, PING it every 15s. On + 2026-09-30 an untouched DB passed 6/6 warm-up PINGs and was dead 25s later; when that happens, no + live result from that box means anything. - **The read-your-writes sync-token bug is FIXED as of `@upstash/redis@1.38.4`** (the repo is pinned `^1.38.4`; `packages/eve`'s peer floor is `>=1.38.4`). Historically, in **1.38.0 and earlier back to 1.34.5**, `HttpClient.request()` built `requestHeaders` from `this.headers` and only *then* copied @@ -647,9 +653,11 @@ and `eve-extension-demo` (a minimal eve scaffold that mounts the extension). `$count`, `$histogram`, `$percentiles`, `$cardinality`. ## Eve framework facts -- **One eve everywhere again: `eve@0.65.0`** in every package and demo (2026-09-23), and **every package - requires it** — `packages/eve` and `packages/eve-extension` both declare `eve: ">=0.65.0"`. (For one - day the repo was split: the extension on 0.64.1, `packages/eve` on 0.63.0, because eve 0.64.0 removed +- **The repo is split again (2026-09-30): `packages/eve-extension` + `examples/eve-extension-demo` are + on `eve@0.68.0` (extension peer `>=0.68.0`); `packages/eve` + `examples/eve-demo` stay on + `eve@0.65.0` (peer `>=0.65.0`)** — see the 0.65.0 → 0.68.0 bump note below. Before that (2026-09-23) + it was one `eve@0.65.0` everywhere, with both packages declaring `eve: ">=0.65.0"`. (For one + day the repo was also split earlier: the extension on 0.64.1, `packages/eve` on 0.63.0, because eve 0.64.0 removed the `SandboxBackend*` authoring types that `packages/eve/src/sandbox.ts` implemented.) eve 0.64 replaced sandbox **backends** with **providers** (`eve/sandbox/provider`: `defineSandboxProvider`, `SandboxProvider*`, `SandboxDeleteOptions`) and object-form `defineSandbox({ backend, bootstrap, @@ -832,6 +840,18 @@ and `eve-extension-demo` (a minimal eve scaffold that mounts the extension). implementation needed **no** new member for 0.55.0 — `pnpm typecheck` is clean across all four packages. Even the extension's compiled output is unchanged: **`_manifest.json` is the only file in `packages/eve-extension/dist` that differs from published `0.10.0`.** +- **The 0.65.0 → 0.68.0 bump (2026-09-30) is EXTENSION-ONLY again.** `packages/eve` cannot take it + without a source migration: eve **0.66.0** (ee286fe) removed `MutableNetworkSandboxSession` from + `eve/sandbox` (network policy became provider-specific; `SandboxSession` lost `setNetworkPolicy`), and + `packages/eve/src/sandbox.ts` + `sandbox.test.ts` import it — tsup's DTS step and `tsc` fail with + `TS2305 … has no exported member 'MutableNetworkSandboxSession'` plus a cascade of implicit-`any` + errors. (Knock-on: `examples/eve-demo`'s `next build` then fails on implicit-`any` in + `agent/channels/eve.ts`, because `@upstash/agentkit-eve` has no `.d.ts`.) The extension needed no source + change: its rebuild re-stamps **tool 55→59, dynamicTool 52→56, hook 25→29**, and the floor moved + `>=0.65.0` → **`>=0.68.0`**, read off each 0.65.0–0.68.0 tarball's + `dist/src/compiler/extension-compatibility.js`. eve 0.68.0 still accepts the old 55/52/25 stamps, so + published `0.13.0` keeps working on it. eve ≥0.64's scaffold also needs `just-bash` for a plain + `eve build`; the extension demo side-steps that with `--skip-sandbox-prewarm` (see its section). - **The 0.64.1 → 0.65.0 bump (2026-09-23, same PR #46) finished what 0.64.1 couldn't: the whole repo is on 0.65.0 and every package requires it.** `packages/eve`'s sandbox was ported from the removed backend API to an eve **provider** (`UpstashSandbox`, see Known issues) — the only source change; diff --git a/examples/eve-extension-demo/package.json b/examples/eve-extension-demo/package.json index c9c6ba3..247b6cc 100644 --- a/examples/eve-extension-demo/package.json +++ b/examples/eve-extension-demo/package.json @@ -19,7 +19,7 @@ "@upstash/redis": "^1.38.4", "@vercel/connect": "0.2.2", "ai": "7.0.107", - "eve": "^0.65.0", + "eve": "^0.68.0", "zod": "4.4.3" }, "devDependencies": { diff --git a/packages/eve-extension/AGENTS.md b/packages/eve-extension/AGENTS.md index fce0f9f..995461b 100644 --- a/packages/eve-extension/AGENTS.md +++ b/packages/eve-extension/AGENTS.md @@ -37,7 +37,7 @@ unavailable, use https://eve.dev/docs/extensions as a fallback. agent-shaped source tree into `dist/extension/`, emits type declarations and a compatibility manifest, and fills the package `exports` map. Ship `dist/` only. `eve` is a required peer so the consumer's eve is the one that runs, but NOT a -wildcard: keep the floor (`>=0.65.0`) in sync with what the built manifest's +wildcard: keep the floor (`>=0.68.0`) in sync with what the built manifest's contracts require, so an incompatible eve fails at install instead of at `eve build` (see issue #22). eve validates the real compatibility from the generated manifest. diff --git a/packages/eve-extension/README.md b/packages/eve-extension/README.md index 7204fb1..52a0d87 100644 --- a/packages/eve-extension/README.md +++ b/packages/eve-extension/README.md @@ -15,7 +15,7 @@ no repeated schemas; upgrades come through the package manager. `` is the mount file's basename — the examples below use `agentkit`. -Start from an eve project (eve ≥ 0.65.0 — the prebuilt extension is built with eve 0.65.0 and its compatibility manifest requires tool contract v55 (dynamicTool v52, hook v25), which eve 0.65.0 is the first release to support; the package declares this as its `eve` peer range), then: +Start from an eve project (eve ≥ 0.68.0 — the prebuilt extension is built with eve 0.68.0 and its compatibility manifest requires tool contract v59 (dynamicTool v56, hook v29), which eve 0.68.0 is the first release to support; the package declares this as its `eve` peer range), then: ```bash pnpm add @upstash/agentkit-eve-extension diff --git a/packages/eve-extension/package.json b/packages/eve-extension/package.json index f9382eb..8fe1a41 100644 --- a/packages/eve-extension/package.json +++ b/packages/eve-extension/package.json @@ -56,10 +56,10 @@ }, "devDependencies": { "@types/node": "24.x", - "eve": "^0.65.0", + "eve": "^0.68.0", "typescript": "7.0.2" }, "peerDependencies": { - "eve": ">=0.65.0" + "eve": ">=0.68.0" } } diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 2546539..46c3601 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -216,13 +216,13 @@ importers: version: 1.38.4 '@vercel/connect': specifier: 0.2.2 - version: 0.2.2(@ai-sdk/mcp@2.0.54(zod@4.4.3))(ai@7.0.107(zod@4.4.3))(eve@0.65.0(@opentelemetry/api@1.9.1)(ai@7.0.107(zod@4.4.3))) + version: 0.2.2(@ai-sdk/mcp@2.0.54(zod@4.4.3))(ai@7.0.107(zod@4.4.3))(eve@0.68.0(@opentelemetry/api@1.9.1)(ai@7.0.107(zod@4.4.3))) ai: specifier: 7.0.107 version: 7.0.107(zod@4.4.3) eve: - specifier: ^0.65.0 - version: 0.65.0(@opentelemetry/api@1.9.1)(ai@7.0.107(zod@4.4.3)) + specifier: ^0.68.0 + version: 0.68.0(@opentelemetry/api@1.9.1)(ai@7.0.107(zod@4.4.3)) zod: specifier: 4.4.3 version: 4.4.3 @@ -303,8 +303,8 @@ importers: specifier: 24.x version: 24.13.2 eve: - specifier: ^0.65.0 - version: 0.65.0(@opentelemetry/api@1.9.1)(ai@7.0.107(zod@4.4.3)) + specifier: ^0.68.0 + version: 0.68.0(@opentelemetry/api@1.9.1)(ai@7.0.107(zod@4.4.3)) typescript: specifier: 7.0.2 version: 7.0.2 @@ -3353,6 +3353,32 @@ packages: microsandbox: optional: true + eve@0.68.0: + resolution: {integrity: sha512-1cvxOdbfESdhZjAdhjUwFJSx0B6uWkbaEvwmau6vNhHNX9A+SZaathd79acDzQNYbOa+5WjsypOx4wa8KjKtgQ==} + engines: {node: '>=24'} + hasBin: true + peerDependencies: + '@opentelemetry/api': ^1.0.0 + ai: ^7.0.105 + braintrust: ^3.0.0 + chat: ^4.41.0 + dd-trace: ^6.13.0 + just-bash: ^3.1.0 + microsandbox: ^0.5.0 + peerDependenciesMeta: + '@opentelemetry/api': + optional: true + braintrust: + optional: true + chat: + optional: true + dd-trace: + optional: true + just-bash: + optional: true + microsandbox: + optional: true + eventsource-parser@3.1.1: resolution: {integrity: sha512-EKN1vKAMcZ8MlYMpaNuxN6R9yakzH6uajHcHVTqWJzvu5pWw9DyhbP35HH8MVBQ+dZjAfDxk+A8NiR9KWaXiyQ==} engines: {node: '>=18.0.0'} @@ -7176,6 +7202,14 @@ snapshots: ai: 7.0.107(zod@4.4.3) eve: 0.65.0(@opentelemetry/api@1.9.1)(ai@7.0.107(zod@4.4.3)) + '@vercel/connect@0.2.2(@ai-sdk/mcp@2.0.54(zod@4.4.3))(ai@7.0.107(zod@4.4.3))(eve@0.68.0(@opentelemetry/api@1.9.1)(ai@7.0.107(zod@4.4.3)))': + dependencies: + '@vercel/oidc': 3.6.1 + optionalDependencies: + '@ai-sdk/mcp': 2.0.54(zod@4.4.3) + ai: 7.0.107(zod@4.4.3) + eve: 0.68.0(@opentelemetry/api@1.9.1)(ai@7.0.107(zod@4.4.3)) + '@vercel/oidc@3.2.0': {} '@vercel/oidc@3.6.1': @@ -7795,6 +7829,14 @@ snapshots: optionalDependencies: '@opentelemetry/api': 1.9.1 + eve@0.68.0(@opentelemetry/api@1.9.1)(ai@7.0.107(zod@4.4.3)): + dependencies: + ai: 7.0.107(zod@4.4.3) + nitro: 3.0.260903-beta + undici: 8.9.0 + optionalDependencies: + '@opentelemetry/api': 1.9.1 + eventsource-parser@3.1.1: {} execa@5.1.1: