5bd9fbe9cd
Three verified, currently-live problems, each closed with real evidence (full trace kept in Neuron memory, tags neuron-technologies/neuron,build-audit): 1. dist/soul.c was stale relative to main's own chat.el (11 commits / 459 lines behind, missing PR #122's OpenAI-tools + agentic-loop work and its two "silently break chat" fixes). tools/soulc-stamp.sh --check confirmed it; tools/build-soul-from-dist.sh correctly refused to build (exit 9). Regenerated and re-stamped. No runnable regen script existed anywhere upstream — added tools/regenerate-soul-amalgam.sh, which reproduces the committed amalgam's exact symbol set (byte-for-byte content match, modulo the genuinely new PR #122 functions) and is documented end-to-end in AGENTS.md, including three real elc/elb toolchain gotchas found and root-caused along the way (stale .elh caches silently truncating builds; elb cannot produce this repo's single-TU amalgam; elc silently drops the first function(s) after a comment block in a flat-concatenated compile). 2. tools/build-soul-from-dist.sh failed to link on macOS (`ld: library 'ssl' not found` — Homebrew's openssl@3 is keg-only) and was missing -lssl -lcrypto entirely, drifted from CI's own working recipe. Fixed: adds -L$(brew --prefix openssl@3)/lib on Darwin, matches CI's link line. Verified: dist/neuron now builds and boots clean on a throwaway port/HOME (never touched the live :7770/:8742). 3. Untracked committed *.elh compiler-header caches (elc/elb prefer a stale cached header over recompiling its source, silently, with no error — this is what caused an under-resolved 251-2541-function amalgam multiple times during this audit before the cause was found). Removed from git, gitignored going forward. Also: AGENTS.md and README.md existed on disk but were never committed (git log on both returned nothing) and documented the pre-collapse ~90-tool MCP surface as current. Committed corrected versions reflecting the live 9-op surface (read/write/relate/supersede/think/attend/assert/ground/learn, merged in #153) and the audit-verified build recipe/port topology. Added connectd/ — a minimal local-dev stub for the neuron-connectd MCP sidecar. routes.el/chat.el call 127.0.0.1:7771 for it right now on every soul boot and agentic turn per a real, detailed 2026-06-13 spec (mcp-connectors-adoption-spec.md); the sidecar itself was never built. Meanwhile :7771 is a live three-way collision (axon's unbuilt-Rust default, this connectd contract, and council — the anti-confabulation service actually running there in prod, which live-answers both other things' requests with unrelated 404s instead of a clean bridge-down signal). This stub only implements the documented contract as "zero connectors configured" for local-dev correctness; it does not attempt OAuth or a real MCP client — that is a real, separate product decision. See connectd/README.md for the full trace and the open question left for Will.
75 lines
3.4 KiB
Bash
Executable File
75 lines
3.4 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# build-soul-from-dist.sh — build a deployable soul from the SAME input CI compiles.
|
|
#
|
|
# THE PROBLEM THIS CLOSES: until now, deploys were built by build-soul.sh, which
|
|
# compiles a scratch amalgam and never touches dist/soul.c. CI compiles dist/soul.c.
|
|
# Two lineages. On 2026-08-09 the committed input fell 2,761 bytes behind the sources
|
|
# while three binaries built the other way were installed on the operator machine —
|
|
# so "what runs" and "what the repo says builds" were different artifacts again,
|
|
# which is the whole of #133 and #111 wearing new clothes.
|
|
#
|
|
# This builds from dist/soul.c with CI's own flags, after asserting that dist/soul.c
|
|
# actually matches the .el sources, and writes a provenance sidecar so a deployer can
|
|
# refuse anything of unknown origin.
|
|
#
|
|
# -rdynamic and -DHAVE_CURL are copied from .gitea/workflows/ci.yaml deliberately.
|
|
# The CI comment explains -rdynamic: without it the runtime cannot resolve its HTTP
|
|
# handler by name via dlsym and the binary serves nothing on every route.
|
|
#
|
|
# usage: build-soul-from-dist.sh <out-binary>
|
|
set -u
|
|
OUT="${1:?usage: build-soul-from-dist.sh <out-binary>}"
|
|
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
|
RUNTIME="$ROOT/vendor/el-runtime/v1.0.0-20260501"
|
|
|
|
cd "$ROOT" || exit 2
|
|
|
|
echo "[build-from-dist] GATE: does dist/soul.c match the sources?"
|
|
if ! ./tools/soulc-stamp.sh --check; then
|
|
echo "[build-from-dist] REFUSING — the build input is stale. Regenerate and stamp first." >&2
|
|
exit 9
|
|
fi
|
|
|
|
[ -f "$RUNTIME/el_runtime.c" ] || { echo "pinned runtime missing at $RUNTIME" >&2; exit 2; }
|
|
|
|
# macOS: Homebrew's openssl@3 is keg-only (never linked into /usr/local or
|
|
# /opt/homebrew directly), so cc/ld cannot find -lssl/-lcrypto without an
|
|
# explicit -L. CI's runner installs libssl-dev system-wide on Ubuntu, so this
|
|
# branch is a no-op there. Discovered 2026-08-15: a plain build on macOS with
|
|
# CI's exact flags fails with "ld: library 'ssl' not found" even though the
|
|
# flags are otherwise correct and CI's own recipe (.gitea/workflows/ci.yaml)
|
|
# links -lssl -lcrypto -lcurl -lpthread -lm, which this script had drifted
|
|
# from (it was missing -lssl -lcrypto entirely).
|
|
SSL_LIBDIR=()
|
|
if [ "$(uname -s)" = "Darwin" ] && command -v brew >/dev/null 2>&1; then
|
|
SSL_PREFIX="$(brew --prefix openssl@3 2>/dev/null || true)"
|
|
[ -n "$SSL_PREFIX" ] && [ -d "$SSL_PREFIX/lib" ] && SSL_LIBDIR=(-L"$SSL_PREFIX/lib")
|
|
fi
|
|
|
|
echo "[build-from-dist] compiling dist/soul.c with CI's flags"
|
|
cc -O2 -DHAVE_CURL -rdynamic -fbracket-depth=1024 \
|
|
-I"$RUNTIME" \
|
|
dist/soul.c \
|
|
"$RUNTIME/el_runtime.c" \
|
|
"${SSL_LIBDIR[@]}" \
|
|
-lssl -lcrypto -lcurl -lpthread -lm \
|
|
-o "$OUT" || { echo "[build-from-dist] COMPILE FAILED" >&2; exit 3; }
|
|
|
|
# Provenance sidecar: what a deployer checks before installing anything.
|
|
SRC_SHA="$(shasum -a 256 dist/soul.c | awk '{print $1}')"
|
|
STAMP_SHA="$(shasum -a 256 dist/soul.c.stamp | awk '{print $1}')"
|
|
COMMIT="$(git rev-parse HEAD 2>/dev/null || echo unknown)"
|
|
DIRTY="clean"; [ -n "$(git status --porcelain -- '*.el' dist/soul.c 2>/dev/null)" ] && DIRTY="DIRTY"
|
|
cat > "$OUT.provenance" <<EOF
|
|
{"built_from":"dist/soul.c",
|
|
"dist_soul_c_sha256":"$SRC_SHA",
|
|
"stamp_sha256":"$STAMP_SHA",
|
|
"git_commit":"$COMMIT",
|
|
"worktree":"$DIRTY",
|
|
"runtime":"vendor/el-runtime/v1.0.0-20260501",
|
|
"flags":"-O2 -DHAVE_CURL -rdynamic"}
|
|
EOF
|
|
|
|
echo "[build-from-dist] OK -> $OUT ($(wc -c < "$OUT" | tr -d ' ') bytes)"
|
|
echo "[build-from-dist] provenance -> $OUT.provenance (commit ${COMMIT:0:8}, worktree $DIRTY)"
|