fix(project): validate runtimeVersion on CodeZip runtimes - #1972

Merged
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version
Aug 21, 2026
Merged

fix(project): validate runtimeVersion on CodeZip runtimes#1972
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version

Conversation

@notgitika

@notgitikanotgitika commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Rebased onto current refactor. Both parents (#1969, #1970) have merged, and refactor has since landed two of this PR's three parts independently — see "What the rebase changed" below.

The gap

The CDK construct library's AgentEnvSpecSchema refines:

if(data.build!=='Container'&&!data.runtimeVersion){// "runtimeVersion is required for CodeZip builds"}

Our copy of that schema marked the field plain .optional(), with no such rule. So the CLI accepted a spec that synthesis would refuse, and the user only discovered it after a full tsc + cdk synth — from a stack trace inside the generated app rather than from the CLI.

Our superRefine already mirrors the library's checks almost one for one, including the identical container-only-fields loop directly beneath. This adds the one that was missing, in the same position the library has it:

if(data.build!=="Container"&&!data.runtimeVersion){ctx.addIssue({code: "custom",message: "runtimeVersion is required for CodeZip builds",path: ["runtimeVersion"],});}

Container builds take their version from the image and stay exempt, consistent with the check below it.

Reporting the rule earlier is only useful if it says what to fix

DeserializationError named the file and nothing else:

Failed to deserialize file at /path/to/agentcore/agentcore.json

The zod issues were attached as cause, which nothing renders — they were reachable only from the debug log. So the user traded CDK's precise runtimes[0].runtimeVersion: runtimeVersion is required for CodeZip builds for a message that doesn't name a field.

DeserializationError now takes an optional detail, and json.read() fills it with z.prettifyError():

Failed to deserialize file at "/path/to/agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion

Putting it in json.read() rather than in the project manager means every caller of json.read() benefits, not just agentcore.json. A JSON syntax error carries no zod issues, so that path is unchanged and still covered by its existing test.

Blast radius

ProjectSpecSchema has exactly one consumer: resolve() at manager.tsx:56. So the only configs this newly rejects are ones the CDK app would also reject at synth — no workflow that previously succeeded starts failing. It does mean the whole CLI now refuses to load such a config rather than failing at build time, which is the intent.

Two test fixtures were CodeZip runtimes without runtimeVersion and are now invalid by this rule, so they gain one (projectSchemas/runtime.test.ts, projectSchemas/project.test.ts). Worth a look during review that the surrounding assertions still test what they claim — the security-group-cap test at runtime.test.ts asserts a CodeZip spec succeeds, so it would have silently started passing for the wrong reason had the fixture not been fixed.

What the rebase changed

Two of the three original commits are now redundant, so the branch is a single commit:

  • Promoting DeserializationError to a USER-sourced AgentCoreCLIError landed on refactor independently. Only the detail option is new here.
  • Removing the try/catch wrapper in resolve() also landed on refactor independently. manager.tsx is no longer touched by this PR at all.
  • The earlier review round replaced a hand-rolled describeValidationFailure with z.prettifyError and moved the detail into json.ts (thanks @Hweinstock). That is the shape above; the intermediate commit no longer stood on its own after the rebase, so the two were squashed.

Verification

Against the same real scaffolded project used to verify #1970, with runtimeVersion removed from its agentcore.json:

  • Before: tsc ran, cdk synth ran, then the construct library's zod error.
  • After: the CLI stops at config load naming runtimes[0].runtimeVersion — no compile, no synth, no node_modules needed.

New unit tests: the rule rejects a CodeZip runtime with no runtimeVersion and reports it at path: ["runtimeVersion"]; a container runtime without one still validates; and resolve() surfaces the reason in its message.

  • bun test — 1600 pass, 2 fail. Both failures are Cannot find package 'aws-cdk-lib' loading the CDK template assets (src/assets/cdk/test/cdk.test.ts), which are meant to run inside a scaffolded project and are unrelated to this diff.
  • tsc --noEmit clean, oxlint clean, prettier --check clean on all six touched files.

@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 11, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 11, 2026
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 305bf56 to 639227fCompareAugust 11, 2026 19:03
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 4c2ac79 to 1ed88a7CompareAugust 12, 2026 19:54
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 12, 2026
@tejaskash
tejaskashforce-pushed the feat/project-build-synth branch from 78097a8 to 0b2da99CompareAugust 12, 2026 20:24
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 0b2da99 to 05c244eCompareAugust 13, 2026 15:25
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ed88a7 to 1ac4641CompareAugust 13, 2026 15:29
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 13, 2026
Base automatically changed from feat/project-build-synth to refactorAugust 13, 2026 16:26
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ac4641 to 86d59dfCompareAugust 13, 2026 18:06
@codecov-commenter

codecov-commenter commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.13%. Comparing base (b03cecb) to head (874a194).
⚠️ Report is 2 commits behind head on refactor.

Additional details and impacted files
@@ Coverage Diff @@## refactor #1972 +/- ##
=========================================
Coverage 97.13% 97.13% =========================================
Files 386 386 Lines 23017 23035 +18 =========================================
+ Hits 22358 22376 +18 
Misses 659 659 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika

Copy link
Copy Markdown
ContributorAuthor

typecheck failing on refactor head and therefore also on this PR

tejaskash
tejaskash previously approved these changes Aug 13, 2026
Comment threadsrc/core/project/manager.tsx Outdated
Comment threadsrc/core/project/manager.tsx Outdated
The CDK construct library rejects a CodeZip runtime that declares no
runtimeVersion, but our own ProjectRuntimeSchema marked the field plain
`.optional()`. The CLI therefore accepted a spec that synthesis would refuse,
and the user only found out after a compile and a synth.
Mirror the library's rule so the CLI reports it against agentcore.json instead.
Container builds take their version from the image and stay exempt, matching the
adjacent container-only-fields check.
Surfacing the rule earlier is only useful if it says what to fix, and
DeserializationError named the file and nothing else -- the zod issues were
reachable only from the debug log. It now takes an optional `detail`, which
json.read() fills with z.prettifyError(), so every caller of json.read()
reports the failing field rather than just the project manager:
Failed to deserialize file at ".../agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion
A JSON syntax error carries no zod issues to render and is unchanged.
Two test fixtures were CodeZip runtimes without runtimeVersion and are now
invalid by this rule, so they gain one.
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from d7475e9 to 874a194CompareAugust 21, 2026 18:52
@notgitika
notgitika merged commit d7f3fd4 into refactorAug 21, 2026
11 checks passed
@notgitika
notgitika deleted the fix/codezip-runtime-version branch August 21, 2026 19:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@notgitika@codecov-commenter@Hweinstock@tejaskash@nborges-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(project): validate runtimeVersion on CodeZip runtimes - #1972

Merged
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version
Aug 21, 2026
Merged

fix(project): validate runtimeVersion on CodeZip runtimes#1972
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version

Conversation

@notgitika

@notgitikanotgitika commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Rebased onto current refactor. Both parents (#1969, #1970) have merged, and refactor has since landed two of this PR's three parts independently — see "What the rebase changed" below.

The gap

The CDK construct library's AgentEnvSpecSchema refines:

if(data.build!=='Container'&&!data.runtimeVersion){// "runtimeVersion is required for CodeZip builds"}

Our copy of that schema marked the field plain .optional(), with no such rule. So the CLI accepted a spec that synthesis would refuse, and the user only discovered it after a full tsc + cdk synth — from a stack trace inside the generated app rather than from the CLI.

Our superRefine already mirrors the library's checks almost one for one, including the identical container-only-fields loop directly beneath. This adds the one that was missing, in the same position the library has it:

if(data.build!=="Container"&&!data.runtimeVersion){ctx.addIssue({code: "custom",message: "runtimeVersion is required for CodeZip builds",path: ["runtimeVersion"],});}

Container builds take their version from the image and stay exempt, consistent with the check below it.

Reporting the rule earlier is only useful if it says what to fix

DeserializationError named the file and nothing else:

Failed to deserialize file at /path/to/agentcore/agentcore.json

The zod issues were attached as cause, which nothing renders — they were reachable only from the debug log. So the user traded CDK's precise runtimes[0].runtimeVersion: runtimeVersion is required for CodeZip builds for a message that doesn't name a field.

DeserializationError now takes an optional detail, and json.read() fills it with z.prettifyError():

Failed to deserialize file at "/path/to/agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion

Putting it in json.read() rather than in the project manager means every caller of json.read() benefits, not just agentcore.json. A JSON syntax error carries no zod issues, so that path is unchanged and still covered by its existing test.

Blast radius

ProjectSpecSchema has exactly one consumer: resolve() at manager.tsx:56. So the only configs this newly rejects are ones the CDK app would also reject at synth — no workflow that previously succeeded starts failing. It does mean the whole CLI now refuses to load such a config rather than failing at build time, which is the intent.

Two test fixtures were CodeZip runtimes without runtimeVersion and are now invalid by this rule, so they gain one (projectSchemas/runtime.test.ts, projectSchemas/project.test.ts). Worth a look during review that the surrounding assertions still test what they claim — the security-group-cap test at runtime.test.ts asserts a CodeZip spec succeeds, so it would have silently started passing for the wrong reason had the fixture not been fixed.

What the rebase changed

Two of the three original commits are now redundant, so the branch is a single commit:

  • Promoting DeserializationError to a USER-sourced AgentCoreCLIError landed on refactor independently. Only the detail option is new here.
  • Removing the try/catch wrapper in resolve() also landed on refactor independently. manager.tsx is no longer touched by this PR at all.
  • The earlier review round replaced a hand-rolled describeValidationFailure with z.prettifyError and moved the detail into json.ts (thanks @Hweinstock). That is the shape above; the intermediate commit no longer stood on its own after the rebase, so the two were squashed.

Verification

Against the same real scaffolded project used to verify #1970, with runtimeVersion removed from its agentcore.json:

  • Before: tsc ran, cdk synth ran, then the construct library's zod error.
  • After: the CLI stops at config load naming runtimes[0].runtimeVersion — no compile, no synth, no node_modules needed.

New unit tests: the rule rejects a CodeZip runtime with no runtimeVersion and reports it at path: ["runtimeVersion"]; a container runtime without one still validates; and resolve() surfaces the reason in its message.

  • bun test — 1600 pass, 2 fail. Both failures are Cannot find package 'aws-cdk-lib' loading the CDK template assets (src/assets/cdk/test/cdk.test.ts), which are meant to run inside a scaffolded project and are unrelated to this diff.
  • tsc --noEmit clean, oxlint clean, prettier --check clean on all six touched files.

@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 11, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 11, 2026
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 305bf56 to 639227fCompareAugust 11, 2026 19:03
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 4c2ac79 to 1ed88a7CompareAugust 12, 2026 19:54
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 12, 2026
@tejaskash
tejaskashforce-pushed the feat/project-build-synth branch from 78097a8 to 0b2da99CompareAugust 12, 2026 20:24
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 0b2da99 to 05c244eCompareAugust 13, 2026 15:25
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ed88a7 to 1ac4641CompareAugust 13, 2026 15:29
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 13, 2026
Base automatically changed from feat/project-build-synth to refactorAugust 13, 2026 16:26
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ac4641 to 86d59dfCompareAugust 13, 2026 18:06
@codecov-commenter

codecov-commenter commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.13%. Comparing base (b03cecb) to head (874a194).
⚠️ Report is 2 commits behind head on refactor.

Additional details and impacted files
@@ Coverage Diff @@## refactor #1972 +/- ##
=========================================
Coverage 97.13% 97.13% =========================================
Files 386 386 Lines 23017 23035 +18 =========================================
+ Hits 22358 22376 +18 
Misses 659 659 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika

Copy link
Copy Markdown
ContributorAuthor

typecheck failing on refactor head and therefore also on this PR

tejaskash
tejaskash previously approved these changes Aug 13, 2026
Comment threadsrc/core/project/manager.tsx Outdated
Comment threadsrc/core/project/manager.tsx Outdated
The CDK construct library rejects a CodeZip runtime that declares no
runtimeVersion, but our own ProjectRuntimeSchema marked the field plain
`.optional()`. The CLI therefore accepted a spec that synthesis would refuse,
and the user only found out after a compile and a synth.
Mirror the library's rule so the CLI reports it against agentcore.json instead.
Container builds take their version from the image and stay exempt, matching the
adjacent container-only-fields check.
Surfacing the rule earlier is only useful if it says what to fix, and
DeserializationError named the file and nothing else -- the zod issues were
reachable only from the debug log. It now takes an optional `detail`, which
json.read() fills with z.prettifyError(), so every caller of json.read()
reports the failing field rather than just the project manager:
Failed to deserialize file at ".../agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion
A JSON syntax error carries no zod issues to render and is unchanged.
Two test fixtures were CodeZip runtimes without runtimeVersion and are now
invalid by this rule, so they gain one.
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from d7475e9 to 874a194CompareAugust 21, 2026 18:52
@notgitika
notgitika merged commit d7f3fd4 into refactorAug 21, 2026
11 checks passed
@notgitika
notgitika deleted the fix/codezip-runtime-version branch August 21, 2026 19:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@notgitika@codecov-commenter@Hweinstock@tejaskash@nborges-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(project): validate runtimeVersion on CodeZip runtimes - #1972

Merged
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version
Aug 21, 2026
Merged

fix(project): validate runtimeVersion on CodeZip runtimes#1972
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version

Conversation

@notgitika

@notgitikanotgitika commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Rebased onto current refactor. Both parents (#1969, #1970) have merged, and refactor has since landed two of this PR's three parts independently — see "What the rebase changed" below.

The gap

The CDK construct library's AgentEnvSpecSchema refines:

if(data.build!=='Container'&&!data.runtimeVersion){// "runtimeVersion is required for CodeZip builds"}

Our copy of that schema marked the field plain .optional(), with no such rule. So the CLI accepted a spec that synthesis would refuse, and the user only discovered it after a full tsc + cdk synth — from a stack trace inside the generated app rather than from the CLI.

Our superRefine already mirrors the library's checks almost one for one, including the identical container-only-fields loop directly beneath. This adds the one that was missing, in the same position the library has it:

if(data.build!=="Container"&&!data.runtimeVersion){ctx.addIssue({code: "custom",message: "runtimeVersion is required for CodeZip builds",path: ["runtimeVersion"],});}

Container builds take their version from the image and stay exempt, consistent with the check below it.

Reporting the rule earlier is only useful if it says what to fix

DeserializationError named the file and nothing else:

Failed to deserialize file at /path/to/agentcore/agentcore.json

The zod issues were attached as cause, which nothing renders — they were reachable only from the debug log. So the user traded CDK's precise runtimes[0].runtimeVersion: runtimeVersion is required for CodeZip builds for a message that doesn't name a field.

DeserializationError now takes an optional detail, and json.read() fills it with z.prettifyError():

Failed to deserialize file at "/path/to/agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion

Putting it in json.read() rather than in the project manager means every caller of json.read() benefits, not just agentcore.json. A JSON syntax error carries no zod issues, so that path is unchanged and still covered by its existing test.

Blast radius

ProjectSpecSchema has exactly one consumer: resolve() at manager.tsx:56. So the only configs this newly rejects are ones the CDK app would also reject at synth — no workflow that previously succeeded starts failing. It does mean the whole CLI now refuses to load such a config rather than failing at build time, which is the intent.

Two test fixtures were CodeZip runtimes without runtimeVersion and are now invalid by this rule, so they gain one (projectSchemas/runtime.test.ts, projectSchemas/project.test.ts). Worth a look during review that the surrounding assertions still test what they claim — the security-group-cap test at runtime.test.ts asserts a CodeZip spec succeeds, so it would have silently started passing for the wrong reason had the fixture not been fixed.

What the rebase changed

Two of the three original commits are now redundant, so the branch is a single commit:

  • Promoting DeserializationError to a USER-sourced AgentCoreCLIError landed on refactor independently. Only the detail option is new here.
  • Removing the try/catch wrapper in resolve() also landed on refactor independently. manager.tsx is no longer touched by this PR at all.
  • The earlier review round replaced a hand-rolled describeValidationFailure with z.prettifyError and moved the detail into json.ts (thanks @Hweinstock). That is the shape above; the intermediate commit no longer stood on its own after the rebase, so the two were squashed.

Verification

Against the same real scaffolded project used to verify #1970, with runtimeVersion removed from its agentcore.json:

  • Before: tsc ran, cdk synth ran, then the construct library's zod error.
  • After: the CLI stops at config load naming runtimes[0].runtimeVersion — no compile, no synth, no node_modules needed.

New unit tests: the rule rejects a CodeZip runtime with no runtimeVersion and reports it at path: ["runtimeVersion"]; a container runtime without one still validates; and resolve() surfaces the reason in its message.

  • bun test — 1600 pass, 2 fail. Both failures are Cannot find package 'aws-cdk-lib' loading the CDK template assets (src/assets/cdk/test/cdk.test.ts), which are meant to run inside a scaffolded project and are unrelated to this diff.
  • tsc --noEmit clean, oxlint clean, prettier --check clean on all six touched files.

@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 11, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 11, 2026
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 305bf56 to 639227fCompareAugust 11, 2026 19:03
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 4c2ac79 to 1ed88a7CompareAugust 12, 2026 19:54
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 12, 2026
@tejaskash
tejaskashforce-pushed the feat/project-build-synth branch from 78097a8 to 0b2da99CompareAugust 12, 2026 20:24
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 0b2da99 to 05c244eCompareAugust 13, 2026 15:25
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ed88a7 to 1ac4641CompareAugust 13, 2026 15:29
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 13, 2026
Base automatically changed from feat/project-build-synth to refactorAugust 13, 2026 16:26
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ac4641 to 86d59dfCompareAugust 13, 2026 18:06
@codecov-commenter

codecov-commenter commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.13%. Comparing base (b03cecb) to head (874a194).
⚠️ Report is 2 commits behind head on refactor.

Additional details and impacted files
@@ Coverage Diff @@## refactor #1972 +/- ##
=========================================
Coverage 97.13% 97.13% =========================================
Files 386 386 Lines 23017 23035 +18 =========================================
+ Hits 22358 22376 +18 
Misses 659 659 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika

Copy link
Copy Markdown
ContributorAuthor

typecheck failing on refactor head and therefore also on this PR

tejaskash
tejaskash previously approved these changes Aug 13, 2026
Comment threadsrc/core/project/manager.tsx Outdated
Comment threadsrc/core/project/manager.tsx Outdated
The CDK construct library rejects a CodeZip runtime that declares no
runtimeVersion, but our own ProjectRuntimeSchema marked the field plain
`.optional()`. The CLI therefore accepted a spec that synthesis would refuse,
and the user only found out after a compile and a synth.
Mirror the library's rule so the CLI reports it against agentcore.json instead.
Container builds take their version from the image and stay exempt, matching the
adjacent container-only-fields check.
Surfacing the rule earlier is only useful if it says what to fix, and
DeserializationError named the file and nothing else -- the zod issues were
reachable only from the debug log. It now takes an optional `detail`, which
json.read() fills with z.prettifyError(), so every caller of json.read()
reports the failing field rather than just the project manager:
Failed to deserialize file at ".../agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion
A JSON syntax error carries no zod issues to render and is unchanged.
Two test fixtures were CodeZip runtimes without runtimeVersion and are now
invalid by this rule, so they gain one.
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from d7475e9 to 874a194CompareAugust 21, 2026 18:52
@notgitika
notgitika merged commit d7f3fd4 into refactorAug 21, 2026
11 checks passed
@notgitika
notgitika deleted the fix/codezip-runtime-version branch August 21, 2026 19:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@notgitika@codecov-commenter@Hweinstock@tejaskash@nborges-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(project): validate runtimeVersion on CodeZip runtimes - #1972

Merged
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version
Aug 21, 2026
Merged

fix(project): validate runtimeVersion on CodeZip runtimes#1972
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version

Conversation

@notgitika

@notgitikanotgitika commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Rebased onto current refactor. Both parents (#1969, #1970) have merged, and refactor has since landed two of this PR's three parts independently — see "What the rebase changed" below.

The gap

The CDK construct library's AgentEnvSpecSchema refines:

if(data.build!=='Container'&&!data.runtimeVersion){// "runtimeVersion is required for CodeZip builds"}

Our copy of that schema marked the field plain .optional(), with no such rule. So the CLI accepted a spec that synthesis would refuse, and the user only discovered it after a full tsc + cdk synth — from a stack trace inside the generated app rather than from the CLI.

Our superRefine already mirrors the library's checks almost one for one, including the identical container-only-fields loop directly beneath. This adds the one that was missing, in the same position the library has it:

if(data.build!=="Container"&&!data.runtimeVersion){ctx.addIssue({code: "custom",message: "runtimeVersion is required for CodeZip builds",path: ["runtimeVersion"],});}

Container builds take their version from the image and stay exempt, consistent with the check below it.

Reporting the rule earlier is only useful if it says what to fix

DeserializationError named the file and nothing else:

Failed to deserialize file at /path/to/agentcore/agentcore.json

The zod issues were attached as cause, which nothing renders — they were reachable only from the debug log. So the user traded CDK's precise runtimes[0].runtimeVersion: runtimeVersion is required for CodeZip builds for a message that doesn't name a field.

DeserializationError now takes an optional detail, and json.read() fills it with z.prettifyError():

Failed to deserialize file at "/path/to/agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion

Putting it in json.read() rather than in the project manager means every caller of json.read() benefits, not just agentcore.json. A JSON syntax error carries no zod issues, so that path is unchanged and still covered by its existing test.

Blast radius

ProjectSpecSchema has exactly one consumer: resolve() at manager.tsx:56. So the only configs this newly rejects are ones the CDK app would also reject at synth — no workflow that previously succeeded starts failing. It does mean the whole CLI now refuses to load such a config rather than failing at build time, which is the intent.

Two test fixtures were CodeZip runtimes without runtimeVersion and are now invalid by this rule, so they gain one (projectSchemas/runtime.test.ts, projectSchemas/project.test.ts). Worth a look during review that the surrounding assertions still test what they claim — the security-group-cap test at runtime.test.ts asserts a CodeZip spec succeeds, so it would have silently started passing for the wrong reason had the fixture not been fixed.

What the rebase changed

Two of the three original commits are now redundant, so the branch is a single commit:

  • Promoting DeserializationError to a USER-sourced AgentCoreCLIError landed on refactor independently. Only the detail option is new here.
  • Removing the try/catch wrapper in resolve() also landed on refactor independently. manager.tsx is no longer touched by this PR at all.
  • The earlier review round replaced a hand-rolled describeValidationFailure with z.prettifyError and moved the detail into json.ts (thanks @Hweinstock). That is the shape above; the intermediate commit no longer stood on its own after the rebase, so the two were squashed.

Verification

Against the same real scaffolded project used to verify #1970, with runtimeVersion removed from its agentcore.json:

  • Before: tsc ran, cdk synth ran, then the construct library's zod error.
  • After: the CLI stops at config load naming runtimes[0].runtimeVersion — no compile, no synth, no node_modules needed.

New unit tests: the rule rejects a CodeZip runtime with no runtimeVersion and reports it at path: ["runtimeVersion"]; a container runtime without one still validates; and resolve() surfaces the reason in its message.

  • bun test — 1600 pass, 2 fail. Both failures are Cannot find package 'aws-cdk-lib' loading the CDK template assets (src/assets/cdk/test/cdk.test.ts), which are meant to run inside a scaffolded project and are unrelated to this diff.
  • tsc --noEmit clean, oxlint clean, prettier --check clean on all six touched files.

@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 11, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 11, 2026
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 305bf56 to 639227fCompareAugust 11, 2026 19:03
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 4c2ac79 to 1ed88a7CompareAugust 12, 2026 19:54
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 12, 2026
@tejaskash
tejaskashforce-pushed the feat/project-build-synth branch from 78097a8 to 0b2da99CompareAugust 12, 2026 20:24
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 0b2da99 to 05c244eCompareAugust 13, 2026 15:25
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ed88a7 to 1ac4641CompareAugust 13, 2026 15:29
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 13, 2026
Base automatically changed from feat/project-build-synth to refactorAugust 13, 2026 16:26
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ac4641 to 86d59dfCompareAugust 13, 2026 18:06
@codecov-commenter

codecov-commenter commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.13%. Comparing base (b03cecb) to head (874a194).
⚠️ Report is 2 commits behind head on refactor.

Additional details and impacted files
@@ Coverage Diff @@## refactor #1972 +/- ##
=========================================
Coverage 97.13% 97.13% =========================================
Files 386 386 Lines 23017 23035 +18 =========================================
+ Hits 22358 22376 +18 
Misses 659 659 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika

Copy link
Copy Markdown
ContributorAuthor

typecheck failing on refactor head and therefore also on this PR

tejaskash
tejaskash previously approved these changes Aug 13, 2026
Comment threadsrc/core/project/manager.tsx Outdated
Comment threadsrc/core/project/manager.tsx Outdated
The CDK construct library rejects a CodeZip runtime that declares no
runtimeVersion, but our own ProjectRuntimeSchema marked the field plain
`.optional()`. The CLI therefore accepted a spec that synthesis would refuse,
and the user only found out after a compile and a synth.
Mirror the library's rule so the CLI reports it against agentcore.json instead.
Container builds take their version from the image and stay exempt, matching the
adjacent container-only-fields check.
Surfacing the rule earlier is only useful if it says what to fix, and
DeserializationError named the file and nothing else -- the zod issues were
reachable only from the debug log. It now takes an optional `detail`, which
json.read() fills with z.prettifyError(), so every caller of json.read()
reports the failing field rather than just the project manager:
Failed to deserialize file at ".../agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion
A JSON syntax error carries no zod issues to render and is unchanged.
Two test fixtures were CodeZip runtimes without runtimeVersion and are now
invalid by this rule, so they gain one.
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from d7475e9 to 874a194CompareAugust 21, 2026 18:52
@notgitika
notgitika merged commit d7f3fd4 into refactorAug 21, 2026
11 checks passed
@notgitika
notgitika deleted the fix/codezip-runtime-version branch August 21, 2026 19:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@notgitika@codecov-commenter@Hweinstock@tejaskash@nborges-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(project): validate runtimeVersion on CodeZip runtimes - #1972

Merged
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version
Aug 21, 2026
Merged

fix(project): validate runtimeVersion on CodeZip runtimes#1972
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version

Conversation

@notgitika

@notgitikanotgitika commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Rebased onto current refactor. Both parents (#1969, #1970) have merged, and refactor has since landed two of this PR's three parts independently — see "What the rebase changed" below.

The gap

The CDK construct library's AgentEnvSpecSchema refines:

if(data.build!=='Container'&&!data.runtimeVersion){// "runtimeVersion is required for CodeZip builds"}

Our copy of that schema marked the field plain .optional(), with no such rule. So the CLI accepted a spec that synthesis would refuse, and the user only discovered it after a full tsc + cdk synth — from a stack trace inside the generated app rather than from the CLI.

Our superRefine already mirrors the library's checks almost one for one, including the identical container-only-fields loop directly beneath. This adds the one that was missing, in the same position the library has it:

if(data.build!=="Container"&&!data.runtimeVersion){ctx.addIssue({code: "custom",message: "runtimeVersion is required for CodeZip builds",path: ["runtimeVersion"],});}

Container builds take their version from the image and stay exempt, consistent with the check below it.

Reporting the rule earlier is only useful if it says what to fix

DeserializationError named the file and nothing else:

Failed to deserialize file at /path/to/agentcore/agentcore.json

The zod issues were attached as cause, which nothing renders — they were reachable only from the debug log. So the user traded CDK's precise runtimes[0].runtimeVersion: runtimeVersion is required for CodeZip builds for a message that doesn't name a field.

DeserializationError now takes an optional detail, and json.read() fills it with z.prettifyError():

Failed to deserialize file at "/path/to/agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion

Putting it in json.read() rather than in the project manager means every caller of json.read() benefits, not just agentcore.json. A JSON syntax error carries no zod issues, so that path is unchanged and still covered by its existing test.

Blast radius

ProjectSpecSchema has exactly one consumer: resolve() at manager.tsx:56. So the only configs this newly rejects are ones the CDK app would also reject at synth — no workflow that previously succeeded starts failing. It does mean the whole CLI now refuses to load such a config rather than failing at build time, which is the intent.

Two test fixtures were CodeZip runtimes without runtimeVersion and are now invalid by this rule, so they gain one (projectSchemas/runtime.test.ts, projectSchemas/project.test.ts). Worth a look during review that the surrounding assertions still test what they claim — the security-group-cap test at runtime.test.ts asserts a CodeZip spec succeeds, so it would have silently started passing for the wrong reason had the fixture not been fixed.

What the rebase changed

Two of the three original commits are now redundant, so the branch is a single commit:

  • Promoting DeserializationError to a USER-sourced AgentCoreCLIError landed on refactor independently. Only the detail option is new here.
  • Removing the try/catch wrapper in resolve() also landed on refactor independently. manager.tsx is no longer touched by this PR at all.
  • The earlier review round replaced a hand-rolled describeValidationFailure with z.prettifyError and moved the detail into json.ts (thanks @Hweinstock). That is the shape above; the intermediate commit no longer stood on its own after the rebase, so the two were squashed.

Verification

Against the same real scaffolded project used to verify #1970, with runtimeVersion removed from its agentcore.json:

  • Before: tsc ran, cdk synth ran, then the construct library's zod error.
  • After: the CLI stops at config load naming runtimes[0].runtimeVersion — no compile, no synth, no node_modules needed.

New unit tests: the rule rejects a CodeZip runtime with no runtimeVersion and reports it at path: ["runtimeVersion"]; a container runtime without one still validates; and resolve() surfaces the reason in its message.

  • bun test — 1600 pass, 2 fail. Both failures are Cannot find package 'aws-cdk-lib' loading the CDK template assets (src/assets/cdk/test/cdk.test.ts), which are meant to run inside a scaffolded project and are unrelated to this diff.
  • tsc --noEmit clean, oxlint clean, prettier --check clean on all six touched files.

@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 11, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 11, 2026
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 305bf56 to 639227fCompareAugust 11, 2026 19:03
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 4c2ac79 to 1ed88a7CompareAugust 12, 2026 19:54
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 12, 2026
@tejaskash
tejaskashforce-pushed the feat/project-build-synth branch from 78097a8 to 0b2da99CompareAugust 12, 2026 20:24
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 0b2da99 to 05c244eCompareAugust 13, 2026 15:25
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ed88a7 to 1ac4641CompareAugust 13, 2026 15:29
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 13, 2026
Base automatically changed from feat/project-build-synth to refactorAugust 13, 2026 16:26
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ac4641 to 86d59dfCompareAugust 13, 2026 18:06
@codecov-commenter

codecov-commenter commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.13%. Comparing base (b03cecb) to head (874a194).
⚠️ Report is 2 commits behind head on refactor.

Additional details and impacted files
@@ Coverage Diff @@## refactor #1972 +/- ##
=========================================
Coverage 97.13% 97.13% =========================================
Files 386 386 Lines 23017 23035 +18 =========================================
+ Hits 22358 22376 +18 
Misses 659 659 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika

Copy link
Copy Markdown
ContributorAuthor

typecheck failing on refactor head and therefore also on this PR

tejaskash
tejaskash previously approved these changes Aug 13, 2026
Comment threadsrc/core/project/manager.tsx Outdated
Comment threadsrc/core/project/manager.tsx Outdated
The CDK construct library rejects a CodeZip runtime that declares no
runtimeVersion, but our own ProjectRuntimeSchema marked the field plain
`.optional()`. The CLI therefore accepted a spec that synthesis would refuse,
and the user only found out after a compile and a synth.
Mirror the library's rule so the CLI reports it against agentcore.json instead.
Container builds take their version from the image and stay exempt, matching the
adjacent container-only-fields check.
Surfacing the rule earlier is only useful if it says what to fix, and
DeserializationError named the file and nothing else -- the zod issues were
reachable only from the debug log. It now takes an optional `detail`, which
json.read() fills with z.prettifyError(), so every caller of json.read()
reports the failing field rather than just the project manager:
Failed to deserialize file at ".../agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion
A JSON syntax error carries no zod issues to render and is unchanged.
Two test fixtures were CodeZip runtimes without runtimeVersion and are now
invalid by this rule, so they gain one.
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from d7475e9 to 874a194CompareAugust 21, 2026 18:52
@notgitika
notgitika merged commit d7f3fd4 into refactorAug 21, 2026
11 checks passed
@notgitika
notgitika deleted the fix/codezip-runtime-version branch August 21, 2026 19:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@notgitika@codecov-commenter@Hweinstock@tejaskash@nborges-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(project): validate runtimeVersion on CodeZip runtimes - #1972

Merged
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version
Aug 21, 2026
Merged

fix(project): validate runtimeVersion on CodeZip runtimes#1972
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version

Conversation

@notgitika

@notgitikanotgitika commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Rebased onto current refactor. Both parents (#1969, #1970) have merged, and refactor has since landed two of this PR's three parts independently — see "What the rebase changed" below.

The gap

The CDK construct library's AgentEnvSpecSchema refines:

if(data.build!=='Container'&&!data.runtimeVersion){// "runtimeVersion is required for CodeZip builds"}

Our copy of that schema marked the field plain .optional(), with no such rule. So the CLI accepted a spec that synthesis would refuse, and the user only discovered it after a full tsc + cdk synth — from a stack trace inside the generated app rather than from the CLI.

Our superRefine already mirrors the library's checks almost one for one, including the identical container-only-fields loop directly beneath. This adds the one that was missing, in the same position the library has it:

if(data.build!=="Container"&&!data.runtimeVersion){ctx.addIssue({code: "custom",message: "runtimeVersion is required for CodeZip builds",path: ["runtimeVersion"],});}

Container builds take their version from the image and stay exempt, consistent with the check below it.

Reporting the rule earlier is only useful if it says what to fix

DeserializationError named the file and nothing else:

Failed to deserialize file at /path/to/agentcore/agentcore.json

The zod issues were attached as cause, which nothing renders — they were reachable only from the debug log. So the user traded CDK's precise runtimes[0].runtimeVersion: runtimeVersion is required for CodeZip builds for a message that doesn't name a field.

DeserializationError now takes an optional detail, and json.read() fills it with z.prettifyError():

Failed to deserialize file at "/path/to/agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion

Putting it in json.read() rather than in the project manager means every caller of json.read() benefits, not just agentcore.json. A JSON syntax error carries no zod issues, so that path is unchanged and still covered by its existing test.

Blast radius

ProjectSpecSchema has exactly one consumer: resolve() at manager.tsx:56. So the only configs this newly rejects are ones the CDK app would also reject at synth — no workflow that previously succeeded starts failing. It does mean the whole CLI now refuses to load such a config rather than failing at build time, which is the intent.

Two test fixtures were CodeZip runtimes without runtimeVersion and are now invalid by this rule, so they gain one (projectSchemas/runtime.test.ts, projectSchemas/project.test.ts). Worth a look during review that the surrounding assertions still test what they claim — the security-group-cap test at runtime.test.ts asserts a CodeZip spec succeeds, so it would have silently started passing for the wrong reason had the fixture not been fixed.

What the rebase changed

Two of the three original commits are now redundant, so the branch is a single commit:

  • Promoting DeserializationError to a USER-sourced AgentCoreCLIError landed on refactor independently. Only the detail option is new here.
  • Removing the try/catch wrapper in resolve() also landed on refactor independently. manager.tsx is no longer touched by this PR at all.
  • The earlier review round replaced a hand-rolled describeValidationFailure with z.prettifyError and moved the detail into json.ts (thanks @Hweinstock). That is the shape above; the intermediate commit no longer stood on its own after the rebase, so the two were squashed.

Verification

Against the same real scaffolded project used to verify #1970, with runtimeVersion removed from its agentcore.json:

  • Before: tsc ran, cdk synth ran, then the construct library's zod error.
  • After: the CLI stops at config load naming runtimes[0].runtimeVersion — no compile, no synth, no node_modules needed.

New unit tests: the rule rejects a CodeZip runtime with no runtimeVersion and reports it at path: ["runtimeVersion"]; a container runtime without one still validates; and resolve() surfaces the reason in its message.

  • bun test — 1600 pass, 2 fail. Both failures are Cannot find package 'aws-cdk-lib' loading the CDK template assets (src/assets/cdk/test/cdk.test.ts), which are meant to run inside a scaffolded project and are unrelated to this diff.
  • tsc --noEmit clean, oxlint clean, prettier --check clean on all six touched files.

@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 11, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 11, 2026
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 305bf56 to 639227fCompareAugust 11, 2026 19:03
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 4c2ac79 to 1ed88a7CompareAugust 12, 2026 19:54
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 12, 2026
@tejaskash
tejaskashforce-pushed the feat/project-build-synth branch from 78097a8 to 0b2da99CompareAugust 12, 2026 20:24
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 0b2da99 to 05c244eCompareAugust 13, 2026 15:25
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ed88a7 to 1ac4641CompareAugust 13, 2026 15:29
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 13, 2026
Base automatically changed from feat/project-build-synth to refactorAugust 13, 2026 16:26
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ac4641 to 86d59dfCompareAugust 13, 2026 18:06
@codecov-commenter

codecov-commenter commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.13%. Comparing base (b03cecb) to head (874a194).
⚠️ Report is 2 commits behind head on refactor.

Additional details and impacted files
@@ Coverage Diff @@## refactor #1972 +/- ##
=========================================
Coverage 97.13% 97.13% =========================================
Files 386 386 Lines 23017 23035 +18 =========================================
+ Hits 22358 22376 +18 
Misses 659 659 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika

Copy link
Copy Markdown
ContributorAuthor

typecheck failing on refactor head and therefore also on this PR

tejaskash
tejaskash previously approved these changes Aug 13, 2026
Comment threadsrc/core/project/manager.tsx Outdated
Comment threadsrc/core/project/manager.tsx Outdated
The CDK construct library rejects a CodeZip runtime that declares no
runtimeVersion, but our own ProjectRuntimeSchema marked the field plain
`.optional()`. The CLI therefore accepted a spec that synthesis would refuse,
and the user only found out after a compile and a synth.
Mirror the library's rule so the CLI reports it against agentcore.json instead.
Container builds take their version from the image and stay exempt, matching the
adjacent container-only-fields check.
Surfacing the rule earlier is only useful if it says what to fix, and
DeserializationError named the file and nothing else -- the zod issues were
reachable only from the debug log. It now takes an optional `detail`, which
json.read() fills with z.prettifyError(), so every caller of json.read()
reports the failing field rather than just the project manager:
Failed to deserialize file at ".../agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion
A JSON syntax error carries no zod issues to render and is unchanged.
Two test fixtures were CodeZip runtimes without runtimeVersion and are now
invalid by this rule, so they gain one.
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from d7475e9 to 874a194CompareAugust 21, 2026 18:52
@notgitika
notgitika merged commit d7f3fd4 into refactorAug 21, 2026
11 checks passed
@notgitika
notgitika deleted the fix/codezip-runtime-version branch August 21, 2026 19:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@notgitika@codecov-commenter@Hweinstock@tejaskash@nborges-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(project): validate runtimeVersion on CodeZip runtimes - #1972

Merged
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version
Aug 21, 2026
Merged

fix(project): validate runtimeVersion on CodeZip runtimes#1972
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version

Conversation

@notgitika

@notgitikanotgitika commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Rebased onto current refactor. Both parents (#1969, #1970) have merged, and refactor has since landed two of this PR's three parts independently — see "What the rebase changed" below.

The gap

The CDK construct library's AgentEnvSpecSchema refines:

if(data.build!=='Container'&&!data.runtimeVersion){// "runtimeVersion is required for CodeZip builds"}

Our copy of that schema marked the field plain .optional(), with no such rule. So the CLI accepted a spec that synthesis would refuse, and the user only discovered it after a full tsc + cdk synth — from a stack trace inside the generated app rather than from the CLI.

Our superRefine already mirrors the library's checks almost one for one, including the identical container-only-fields loop directly beneath. This adds the one that was missing, in the same position the library has it:

if(data.build!=="Container"&&!data.runtimeVersion){ctx.addIssue({code: "custom",message: "runtimeVersion is required for CodeZip builds",path: ["runtimeVersion"],});}

Container builds take their version from the image and stay exempt, consistent with the check below it.

Reporting the rule earlier is only useful if it says what to fix

DeserializationError named the file and nothing else:

Failed to deserialize file at /path/to/agentcore/agentcore.json

The zod issues were attached as cause, which nothing renders — they were reachable only from the debug log. So the user traded CDK's precise runtimes[0].runtimeVersion: runtimeVersion is required for CodeZip builds for a message that doesn't name a field.

DeserializationError now takes an optional detail, and json.read() fills it with z.prettifyError():

Failed to deserialize file at "/path/to/agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion

Putting it in json.read() rather than in the project manager means every caller of json.read() benefits, not just agentcore.json. A JSON syntax error carries no zod issues, so that path is unchanged and still covered by its existing test.

Blast radius

ProjectSpecSchema has exactly one consumer: resolve() at manager.tsx:56. So the only configs this newly rejects are ones the CDK app would also reject at synth — no workflow that previously succeeded starts failing. It does mean the whole CLI now refuses to load such a config rather than failing at build time, which is the intent.

Two test fixtures were CodeZip runtimes without runtimeVersion and are now invalid by this rule, so they gain one (projectSchemas/runtime.test.ts, projectSchemas/project.test.ts). Worth a look during review that the surrounding assertions still test what they claim — the security-group-cap test at runtime.test.ts asserts a CodeZip spec succeeds, so it would have silently started passing for the wrong reason had the fixture not been fixed.

What the rebase changed

Two of the three original commits are now redundant, so the branch is a single commit:

  • Promoting DeserializationError to a USER-sourced AgentCoreCLIError landed on refactor independently. Only the detail option is new here.
  • Removing the try/catch wrapper in resolve() also landed on refactor independently. manager.tsx is no longer touched by this PR at all.
  • The earlier review round replaced a hand-rolled describeValidationFailure with z.prettifyError and moved the detail into json.ts (thanks @Hweinstock). That is the shape above; the intermediate commit no longer stood on its own after the rebase, so the two were squashed.

Verification

Against the same real scaffolded project used to verify #1970, with runtimeVersion removed from its agentcore.json:

  • Before: tsc ran, cdk synth ran, then the construct library's zod error.
  • After: the CLI stops at config load naming runtimes[0].runtimeVersion — no compile, no synth, no node_modules needed.

New unit tests: the rule rejects a CodeZip runtime with no runtimeVersion and reports it at path: ["runtimeVersion"]; a container runtime without one still validates; and resolve() surfaces the reason in its message.

  • bun test — 1600 pass, 2 fail. Both failures are Cannot find package 'aws-cdk-lib' loading the CDK template assets (src/assets/cdk/test/cdk.test.ts), which are meant to run inside a scaffolded project and are unrelated to this diff.
  • tsc --noEmit clean, oxlint clean, prettier --check clean on all six touched files.

@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 11, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 11, 2026
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 305bf56 to 639227fCompareAugust 11, 2026 19:03
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 4c2ac79 to 1ed88a7CompareAugust 12, 2026 19:54
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 12, 2026
@tejaskash
tejaskashforce-pushed the feat/project-build-synth branch from 78097a8 to 0b2da99CompareAugust 12, 2026 20:24
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 0b2da99 to 05c244eCompareAugust 13, 2026 15:25
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ed88a7 to 1ac4641CompareAugust 13, 2026 15:29
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 13, 2026
Base automatically changed from feat/project-build-synth to refactorAugust 13, 2026 16:26
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ac4641 to 86d59dfCompareAugust 13, 2026 18:06
@codecov-commenter

codecov-commenter commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.13%. Comparing base (b03cecb) to head (874a194).
⚠️ Report is 2 commits behind head on refactor.

Additional details and impacted files
@@ Coverage Diff @@## refactor #1972 +/- ##
=========================================
Coverage 97.13% 97.13% =========================================
Files 386 386 Lines 23017 23035 +18 =========================================
+ Hits 22358 22376 +18 
Misses 659 659 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika

Copy link
Copy Markdown
ContributorAuthor

typecheck failing on refactor head and therefore also on this PR

tejaskash
tejaskash previously approved these changes Aug 13, 2026
Comment threadsrc/core/project/manager.tsx Outdated
Comment threadsrc/core/project/manager.tsx Outdated
The CDK construct library rejects a CodeZip runtime that declares no
runtimeVersion, but our own ProjectRuntimeSchema marked the field plain
`.optional()`. The CLI therefore accepted a spec that synthesis would refuse,
and the user only found out after a compile and a synth.
Mirror the library's rule so the CLI reports it against agentcore.json instead.
Container builds take their version from the image and stay exempt, matching the
adjacent container-only-fields check.
Surfacing the rule earlier is only useful if it says what to fix, and
DeserializationError named the file and nothing else -- the zod issues were
reachable only from the debug log. It now takes an optional `detail`, which
json.read() fills with z.prettifyError(), so every caller of json.read()
reports the failing field rather than just the project manager:
Failed to deserialize file at ".../agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion
A JSON syntax error carries no zod issues to render and is unchanged.
Two test fixtures were CodeZip runtimes without runtimeVersion and are now
invalid by this rule, so they gain one.
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from d7475e9 to 874a194CompareAugust 21, 2026 18:52
@notgitika
notgitika merged commit d7f3fd4 into refactorAug 21, 2026
11 checks passed
@notgitika
notgitika deleted the fix/codezip-runtime-version branch August 21, 2026 19:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@notgitika@codecov-commenter@Hweinstock@tejaskash@nborges-aws
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(project): validate runtimeVersion on CodeZip runtimes - #1972

Merged
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version
Aug 21, 2026
Merged

fix(project): validate runtimeVersion on CodeZip runtimes#1972
notgitika merged 1 commit into
refactorfrom
fix/codezip-runtime-version

Conversation

@notgitika

@notgitikanotgitika commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Rebased onto current refactor. Both parents (#1969, #1970) have merged, and refactor has since landed two of this PR's three parts independently — see "What the rebase changed" below.

The gap

The CDK construct library's AgentEnvSpecSchema refines:

if(data.build!=='Container'&&!data.runtimeVersion){// "runtimeVersion is required for CodeZip builds"}

Our copy of that schema marked the field plain .optional(), with no such rule. So the CLI accepted a spec that synthesis would refuse, and the user only discovered it after a full tsc + cdk synth — from a stack trace inside the generated app rather than from the CLI.

Our superRefine already mirrors the library's checks almost one for one, including the identical container-only-fields loop directly beneath. This adds the one that was missing, in the same position the library has it:

if(data.build!=="Container"&&!data.runtimeVersion){ctx.addIssue({code: "custom",message: "runtimeVersion is required for CodeZip builds",path: ["runtimeVersion"],});}

Container builds take their version from the image and stay exempt, consistent with the check below it.

Reporting the rule earlier is only useful if it says what to fix

DeserializationError named the file and nothing else:

Failed to deserialize file at /path/to/agentcore/agentcore.json

The zod issues were attached as cause, which nothing renders — they were reachable only from the debug log. So the user traded CDK's precise runtimes[0].runtimeVersion: runtimeVersion is required for CodeZip builds for a message that doesn't name a field.

DeserializationError now takes an optional detail, and json.read() fills it with z.prettifyError():

Failed to deserialize file at "/path/to/agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion

Putting it in json.read() rather than in the project manager means every caller of json.read() benefits, not just agentcore.json. A JSON syntax error carries no zod issues, so that path is unchanged and still covered by its existing test.

Blast radius

ProjectSpecSchema has exactly one consumer: resolve() at manager.tsx:56. So the only configs this newly rejects are ones the CDK app would also reject at synth — no workflow that previously succeeded starts failing. It does mean the whole CLI now refuses to load such a config rather than failing at build time, which is the intent.

Two test fixtures were CodeZip runtimes without runtimeVersion and are now invalid by this rule, so they gain one (projectSchemas/runtime.test.ts, projectSchemas/project.test.ts). Worth a look during review that the surrounding assertions still test what they claim — the security-group-cap test at runtime.test.ts asserts a CodeZip spec succeeds, so it would have silently started passing for the wrong reason had the fixture not been fixed.

What the rebase changed

Two of the three original commits are now redundant, so the branch is a single commit:

  • Promoting DeserializationError to a USER-sourced AgentCoreCLIError landed on refactor independently. Only the detail option is new here.
  • Removing the try/catch wrapper in resolve() also landed on refactor independently. manager.tsx is no longer touched by this PR at all.
  • The earlier review round replaced a hand-rolled describeValidationFailure with z.prettifyError and moved the detail into json.ts (thanks @Hweinstock). That is the shape above; the intermediate commit no longer stood on its own after the rebase, so the two were squashed.

Verification

Against the same real scaffolded project used to verify #1970, with runtimeVersion removed from its agentcore.json:

  • Before: tsc ran, cdk synth ran, then the construct library's zod error.
  • After: the CLI stops at config load naming runtimes[0].runtimeVersion — no compile, no synth, no node_modules needed.

New unit tests: the rule rejects a CodeZip runtime with no runtimeVersion and reports it at path: ["runtimeVersion"]; a container runtime without one still validates; and resolve() surfaces the reason in its message.

  • bun test — 1600 pass, 2 fail. Both failures are Cannot find package 'aws-cdk-lib' loading the CDK template assets (src/assets/cdk/test/cdk.test.ts), which are meant to run inside a scaffolded project and are unrelated to this diff.
  • tsc --noEmit clean, oxlint clean, prettier --check clean on all six touched files.

@github-actionsgithub-actionsBot added the size/s PR size: S label Aug 11, 2026
@github-actionsgithub-actionsBot added agentcore-harness-reviewing AgentCore Harness review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 11, 2026
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 305bf56 to 639227fCompareAugust 11, 2026 19:03
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 4c2ac79 to 1ed88a7CompareAugust 12, 2026 19:54
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 12, 2026
@tejaskash
tejaskashforce-pushed the feat/project-build-synth branch from 78097a8 to 0b2da99CompareAugust 12, 2026 20:24
@notgitika
notgitikaforce-pushed the feat/project-build-synth branch from 0b2da99 to 05c244eCompareAugust 13, 2026 15:25
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ed88a7 to 1ac4641CompareAugust 13, 2026 15:29
@github-actionsgithub-actionsBot added size/s PR size: S and removed size/s PR size: S labels Aug 13, 2026
Base automatically changed from feat/project-build-synth to refactorAugust 13, 2026 16:26
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from 1ac4641 to 86d59dfCompareAugust 13, 2026 18:06
@codecov-commenter

codecov-commenter commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.13%. Comparing base (b03cecb) to head (874a194).
⚠️ Report is 2 commits behind head on refactor.

Additional details and impacted files
@@ Coverage Diff @@## refactor #1972 +/- ##
=========================================
Coverage 97.13% 97.13% =========================================
Files 386 386 Lines 23017 23035 +18 =========================================
+ Hits 22358 22376 +18 
Misses 659 659 

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@notgitika

Copy link
Copy Markdown
ContributorAuthor

typecheck failing on refactor head and therefore also on this PR

tejaskash
tejaskash previously approved these changes Aug 13, 2026
Comment threadsrc/core/project/manager.tsx Outdated
Comment threadsrc/core/project/manager.tsx Outdated
The CDK construct library rejects a CodeZip runtime that declares no
runtimeVersion, but our own ProjectRuntimeSchema marked the field plain
`.optional()`. The CLI therefore accepted a spec that synthesis would refuse,
and the user only found out after a compile and a synth.
Mirror the library's rule so the CLI reports it against agentcore.json instead.
Container builds take their version from the image and stay exempt, matching the
adjacent container-only-fields check.
Surfacing the rule earlier is only useful if it says what to fix, and
DeserializationError named the file and nothing else -- the zod issues were
reachable only from the debug log. It now takes an optional `detail`, which
json.read() fills with z.prettifyError(), so every caller of json.read()
reports the failing field rather than just the project manager:
Failed to deserialize file at ".../agentcore/agentcore.json"
✖ runtimeVersion is required for CodeZip builds
→ at runtimes[0].runtimeVersion
A JSON syntax error carries no zod issues to render and is unchanged.
Two test fixtures were CodeZip runtimes without runtimeVersion and are now
invalid by this rule, so they gain one.
@notgitika
notgitikaforce-pushed the fix/codezip-runtime-version branch from d7475e9 to 874a194CompareAugust 21, 2026 18:52
@notgitika
notgitika merged commit d7f3fd4 into refactorAug 21, 2026
11 checks passed
@notgitika
notgitika deleted the fix/codezip-runtime-version branch August 21, 2026 19:15
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/sPR size: S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@notgitika@codecov-commenter@Hweinstock@tejaskash@nborges-aws