#!/usr/bin/env bash # soulc-stamp.sh — make it impossible for dist/soul.c to drift from the sources # in silence. # # THE PROBLEM (neuron#133, and its own words): "Nothing in the tree regenerates # this file. Only a human running the recipe. It lags in batches, never # per-change, and it will drift again." # # It drifted. On 2026-08-07 a CI or GKE build off main would have shipped an # engine with NONE of five merged fixes — including a P0 safety fix — while # main's source read as correct. CI compiles dist/soul.c, not the .el files, so # the source being right is not the same as the build being right. # # WHY A STAMP AND NOT AUTO-REGENERATION: the CI workflow says elc cannot run on # the runner ("elb on Linux would OOM the runner (elc uses 24GB+ virtual memory # on a 16GB host)"). So the build cannot regenerate the file itself. What it CAN # do, for free and with no compiler, is refuse to compile a stale one. # # The stamp records a fingerprint of every .el source that feeds the amalgam at # the moment it was generated. --check recomputes and compares. Divergence is a # build failure with the recipe in the message, not a silent ship. # # soulc-stamp.sh --write after regenerating dist/soul.c (records the fingerprint) # soulc-stamp.sh --check in CI, before the compile (fails on drift) set -u MODE="${1:---check}" ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" STAMP="$ROOT/dist/soul.c.stamp" AMALGAM="$ROOT/dist/soul.c" # Every .el at the repo root is an input to the amalgam. Sorted so the hash is # order-independent; content-only so timestamps and checkouts do not perturb it. fingerprint() { ( cd "$ROOT" || exit 1 for f in $(ls -1 *.el 2>/dev/null | sort); do printf '%s %s\n' "$(shasum -a 256 "$f" | awk '{print $1}')" "$f" done ) } case "$MODE" in --write) [ -f "$AMALGAM" ] || { echo "no dist/soul.c to stamp — regenerate it first" >&2; exit 2; } { echo "# soul.c.stamp — fingerprint of the .el sources dist/soul.c was generated from." echo "# Written by tools/soulc-stamp.sh --write. Do not hand-edit." echo "# generated_amalgam_sha256 $(shasum -a 256 "$AMALGAM" | awk '{print $1}')" echo "# generated_amalgam_bytes $(wc -c < "$AMALGAM" | tr -d ' ')" fingerprint } > "$STAMP" echo "stamped $(fingerprint | wc -l | tr -d ' ') sources -> dist/soul.c.stamp" ;; --check) if [ ! -f "$STAMP" ]; then echo "FAIL: dist/soul.c.stamp is missing — the build input is unverifiable." >&2 echo " Regenerate the amalgam, then: tools/soulc-stamp.sh --write" >&2 exit 1 fi RECORDED="$(grep -v '^#' "$STAMP")" CURRENT="$(fingerprint)" if [ "$RECORDED" = "$CURRENT" ]; then echo "soulc-stamp: OK — dist/soul.c matches the .el sources" exit 0 fi echo "FAIL: dist/soul.c is STALE. It does not match the current .el sources." >&2 echo "" >&2 echo "CI compiles dist/soul.c, not the .el files. Shipping this means shipping" >&2 echo "an engine that does not contain the merged source. That is neuron#133," >&2 echo "which once hid five merged fixes including a P0 safety fix." >&2 echo "" >&2 echo "Sources that changed since the amalgam was generated:" >&2 diff <(printf '%s\n' "$RECORDED") <(printf '%s\n' "$CURRENT") \ | grep -E '^[<>]' | awk '{print " " $1 " " $3}' | sort -u >&2 echo "" >&2 echo "Fix: regenerate the amalgam, then tools/soulc-stamp.sh --write" >&2 exit 1 ;; *) echo "usage: soulc-stamp.sh [--check|--write]" >&2; exit 2 ;; esac