upgrade-cell-npm-unpublished-package-etarget
Done. Solution written to /workspace/solution.md (evidence in /workspace/evidence.md).
Root cause: bunker-qa.sh's detect_upgrade_inputs() treated any npm package.json as publishable. For heading, the root manifest is "private": true and has no publishable nested workspace, so no heading@<ver> can ever exist on the registry. The upgrade cell's npm install -g heading@0.7.0 was therefore a guaranteed ETARGET/E404 — a harness-premise failure, not a product defect.
Fix (mirrors the proven Go-binary tree-upgrade arm):
1. Added _npm_pkg_publishable / _npm_publishable_nested probes.
2. detect_upgrade_inputs() now sets DETECT_UP_PREV_DIR=qa-up-prev-npm and UP_MODE=tree when a private root has no publishable nested candidate; publishable repos and monorepos with a publishable workspace still use the registry.
3. Generalized ship_prev_tag_tree <tag> <dest> <marker> to pre-clear stale trees, stream git archive, and verify the per-ecosystem manifest (go.mod vs package.json).
4. Generated script derives UP_PREV from DETECT_UP_PREV_DIR and its EXIT trap cleans both ~/qa-up-prev-go and ~/qa-up-prev-npm.
Verification performed:
- Confirmed npm view heading versions → [0.0.1-security] and reproduced the exact ETARGET notarget heading@0.7.0.
- Detector truth table: private/no-candidate → tree arm; private+workspace and public → registry.
- ship_prev_tag_tree test proved streaming, stale pre-clear, marker rejection, and that the working tree is untouched.
Note: the actual home-repo source was not mounted in this sandbox, so the patch is reconstructed from the described design (DETECT_UP_PREV_DIR, ship_prev_tag_tree, UP_PREV) and validated with a standalone harness replicating those functions.
# Evidence - Problem class: upgrade-cell-npm-unpublished-package-etarget - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-25T02:31:27.497Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "bunker-qa.sh upgrade cell runs `npm install -g <pkg>@<ver>` for ANY npm-ecosystem repo with release tags, but a repo whose root package.json is private:true with no publishable nested candidate (heading: only squatter 0.0.1-security on npm) has NO registry artifact \u2014 the cell is guaranteed ETARGET/E404 and grades a FAIL that is a harness premise failure, not a product defect. Fix: detect_upgrade_inputs marks non-publishable npm repos (DETECT_UP_PREV_DIR), ship_prev_tag_tree generalizes to stream the previous tag's tree to ~/qa-up-prev-npm (stale pre-clear, package.json verify), and the generated script's UP_PREV materialization + streamed-arm cleanup cover the npm dir \u2014 same shape as the proven Go-binary tree-upgrade arm.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "upgrade-cell-npm-unpublished-package-etarget", "provider": "openrouter", "solved_at": "2026-09-25T02:31:27.498Z", "version": ""}