9fd8c11670
#133 regenerated the amalgam once and said so itself: 'Nothing in the tree regenerates this file. Only a human running the recipe. It lags in batches, never per-change, and it will drift again.' It drifted again. Every binary deployed on 2026-08-09 was built by build-soul.sh from a scratch amalgam that never touches dist/soul.c, so the committed build input fell 2,761 bytes behind the sources by a different route than #133 describes. Auto-regeneration is not available: the CI workflow records that elc needs 24GB+ of virtual memory and would OOM the runner. So the build cannot regenerate the file. It can refuse to compile a stale one, for free and with no compiler. tools/soulc-stamp.sh records a content fingerprint of every .el source at the moment the amalgam is generated. --check recomputes and compares; divergence exits 1 and names the changed files and the recipe. Wired into CI ahead of the compile. dist/soul.c regenerated from current sources: 1,176,361 -> 1,179,122 bytes, 1,247 inlined bodies (gate wants >=1200), and verified to compile clean at 903,552 bytes. Demonstrated to FAIL on the bad input, per postmortem 0004's rule that a gate which only passes on good input proves nothing: fresh stamp -> OK, exit 0 one .el modified -> FAIL, exit 1, names memory.el source restored -> OK, exit 0 Refs #133, #111 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
84 lines
3.5 KiB
Bash
Executable File
84 lines
3.5 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# soulc-stamp.sh — make it impossible for dist/soul.c to drift from the sources
|
|
# in silence.
|
|
#
|
|
# THE PROBLEM (neuron#133, and its own words): "Nothing in the tree regenerates
|
|
# this file. Only a human running the recipe. It lags in batches, never
|
|
# per-change, and it will drift again."
|
|
#
|
|
# It drifted. On 2026-08-07 a CI or GKE build off main would have shipped an
|
|
# engine with NONE of five merged fixes — including a P0 safety fix — while
|
|
# main's source read as correct. CI compiles dist/soul.c, not the .el files, so
|
|
# the source being right is not the same as the build being right.
|
|
#
|
|
# WHY A STAMP AND NOT AUTO-REGENERATION: the CI workflow says elc cannot run on
|
|
# the runner ("elb on Linux would OOM the runner (elc uses 24GB+ virtual memory
|
|
# on a 16GB host)"). So the build cannot regenerate the file itself. What it CAN
|
|
# do, for free and with no compiler, is refuse to compile a stale one.
|
|
#
|
|
# The stamp records a fingerprint of every .el source that feeds the amalgam at
|
|
# the moment it was generated. --check recomputes and compares. Divergence is a
|
|
# build failure with the recipe in the message, not a silent ship.
|
|
#
|
|
# soulc-stamp.sh --write after regenerating dist/soul.c (records the fingerprint)
|
|
# soulc-stamp.sh --check in CI, before the compile (fails on drift)
|
|
set -u
|
|
MODE="${1:---check}"
|
|
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
|
STAMP="$ROOT/dist/soul.c.stamp"
|
|
AMALGAM="$ROOT/dist/soul.c"
|
|
|
|
# Every .el at the repo root is an input to the amalgam. Sorted so the hash is
|
|
# order-independent; content-only so timestamps and checkouts do not perturb it.
|
|
fingerprint() {
|
|
(
|
|
cd "$ROOT" || exit 1
|
|
for f in $(ls -1 *.el 2>/dev/null | sort); do
|
|
printf '%s %s\n' "$(shasum -a 256 "$f" | awk '{print $1}')" "$f"
|
|
done
|
|
)
|
|
}
|
|
|
|
case "$MODE" in
|
|
--write)
|
|
[ -f "$AMALGAM" ] || { echo "no dist/soul.c to stamp — regenerate it first" >&2; exit 2; }
|
|
{
|
|
echo "# soul.c.stamp — fingerprint of the .el sources dist/soul.c was generated from."
|
|
echo "# Written by tools/soulc-stamp.sh --write. Do not hand-edit."
|
|
echo "# generated_amalgam_sha256 $(shasum -a 256 "$AMALGAM" | awk '{print $1}')"
|
|
echo "# generated_amalgam_bytes $(wc -c < "$AMALGAM" | tr -d ' ')"
|
|
fingerprint
|
|
} > "$STAMP"
|
|
echo "stamped $(fingerprint | wc -l | tr -d ' ') sources -> dist/soul.c.stamp"
|
|
;;
|
|
|
|
--check)
|
|
if [ ! -f "$STAMP" ]; then
|
|
echo "FAIL: dist/soul.c.stamp is missing — the build input is unverifiable." >&2
|
|
echo " Regenerate the amalgam, then: tools/soulc-stamp.sh --write" >&2
|
|
exit 1
|
|
fi
|
|
RECORDED="$(grep -v '^#' "$STAMP")"
|
|
CURRENT="$(fingerprint)"
|
|
if [ "$RECORDED" = "$CURRENT" ]; then
|
|
echo "soulc-stamp: OK — dist/soul.c matches the .el sources"
|
|
exit 0
|
|
fi
|
|
echo "FAIL: dist/soul.c is STALE. It does not match the current .el sources." >&2
|
|
echo "" >&2
|
|
echo "CI compiles dist/soul.c, not the .el files. Shipping this means shipping" >&2
|
|
echo "an engine that does not contain the merged source. That is neuron#133," >&2
|
|
echo "which once hid five merged fixes including a P0 safety fix." >&2
|
|
echo "" >&2
|
|
echo "Sources that changed since the amalgam was generated:" >&2
|
|
diff <(printf '%s\n' "$RECORDED") <(printf '%s\n' "$CURRENT") \
|
|
| grep -E '^[<>]' | awk '{print " " $1 " " $3}' | sort -u >&2
|
|
echo "" >&2
|
|
echo "Fix: regenerate the amalgam, then tools/soulc-stamp.sh --write" >&2
|
|
exit 1
|
|
;;
|
|
|
|
*)
|
|
echo "usage: soulc-stamp.sh [--check|--write]" >&2; exit 2 ;;
|
|
esac
|