What changes, and when
rainlanguage/rainix#392 adds a
codegen witness to the rainix-copy-artifacts reusable workflow. This repo's
.github/workflows/git-clean.yaml calls that workflow at @main, so the check
arrives the moment #392 merges — not when this repo chooses to adopt it. The
next push after that merge fails until a manifest is committed.
Why the check exists
rainix-copy-artifacts currency-checks committed generated sources by re-running
the codegen hooks and then git diff --exit-code. That proves the committed
content is current, but it is structurally blind to a generator that has
stopped emitting a file: the committed copy is already correct, so nothing is
rewritten, nothing differs, and the job is green over a dead emitter. Reproduced
with a control in
rainlanguage/rain.factory.deploy#35.
Seeing that needs an independent statement of which committed files are
generated. That is script/codegen-manifest.txt: one repo-relative path per line,
# comments and blank lines ignored. The witness marks every git-tracked file's
mtime before the first hook and verifys after the last, calling a file
written when it exists and its mtime moved. Any declared path nothing wrote
fails the job by name.
Why this repo is affected
Hooks present: script/Build.sol, script/build.sh. No
script/codegen-manifest.txt today.
What to add
script/codegen-manifest.txt:
meta/PythFtsoSubParserAuthoringMeta.rain.meta
meta/PythWords.rain.meta
src/generated/PythWordsPointers.sol
How that was derived
script/build.sh runs forge script ./script/BuildAuthoringMeta.sol, whose
vm.writeFileBinary target is meta/PythFtsoSubParserAuthoringMeta.rain.meta;
then rain meta build ... -o meta/PythWords.rain.meta.
script/Build.sol calls
LibFs.buildFileForContract(vm, ..., "PythWordsPointers", ...) →
src/generated/PythWordsPointers.sol.
The committed file that must NOT be listed
meta/PythFtsoWords.rain.meta is committed but no hook writes it. build.sh
emits meta/PythWords.rain.meta; nothing in this repo emits PythFtsoWords. It
reads as a leftover from a rename that the current git diff check cannot see —
exactly the class of thing this manifest exists to make visible, and the reason it
is excluded above rather than declared.
Listing it would red the job. Deleting it, if nothing reads it, is the other
resolution — but that is a separate call from adopting the manifest, so this issue
does not assume it.
Reconciling against the job
The failing verify step prints the manifest that run would justify — the set
of git-tracked files the hooks actually wrote in CI. Treat that printout as the
oracle and the list above as a cross-check derived by reading the hooks. A
difference either way is information, not noise:
- listed above, absent from the printout — that emitter may already be dead, or
the file is generated by something the copy-artifacts job does not run.
- printed, absent from above — an incidental write inside the witness window
(forge build is in there), or a generated file this reading missed.
Undeclared-but-written paths are a printed note, never a failure — the check is
a subset assertion, not set equality — so a conservative first manifest is safe and
an over-eager one is not.
Adoption
One commit adding script/codegen-manifest.txt. No workflow edit and no
RAINIX_SHA bump: #392 wires the witness as a composite action resolved at
@main, so nothing in this repo pins the check's version.
Filed while tracking the org-wide adoption cost of rainlanguage/rainix#392. The
paths above were derived by reading this repo's own hooks and committed tree, not
by running the job.
What changes, and when
rainlanguage/rainix#392 adds a
codegen witness to the
rainix-copy-artifactsreusable workflow. This repo's.github/workflows/git-clean.yamlcalls that workflow at@main, so the checkarrives the moment #392 merges — not when this repo chooses to adopt it. The
next push after that merge fails until a manifest is committed.
Why the check exists
rainix-copy-artifactscurrency-checks committed generated sources by re-runningthe codegen hooks and then
git diff --exit-code. That proves the committedcontent is current, but it is structurally blind to a generator that has
stopped emitting a file: the committed copy is already correct, so nothing is
rewritten, nothing differs, and the job is green over a dead emitter. Reproduced
with a control in
rainlanguage/rain.factory.deploy#35.
Seeing that needs an independent statement of which committed files are
generated. That is
script/codegen-manifest.txt: one repo-relative path per line,#comments and blank lines ignored. The witnessmarks every git-tracked file'smtime before the first hook and
verifys after the last, calling a filewritten when it exists and its mtime moved. Any declared path nothing wrote
fails the job by name.
Why this repo is affected
Hooks present:
script/Build.sol,script/build.sh. Noscript/codegen-manifest.txttoday.What to add
script/codegen-manifest.txt:How that was derived
script/build.shrunsforge script ./script/BuildAuthoringMeta.sol, whosevm.writeFileBinarytarget ismeta/PythFtsoSubParserAuthoringMeta.rain.meta;then
rain meta build ... -o meta/PythWords.rain.meta.script/Build.solcallsLibFs.buildFileForContract(vm, ..., "PythWordsPointers", ...)→src/generated/PythWordsPointers.sol.The committed file that must NOT be listed
meta/PythFtsoWords.rain.metais committed but no hook writes it.build.shemits
meta/PythWords.rain.meta; nothing in this repo emitsPythFtsoWords. Itreads as a leftover from a rename that the current
git diffcheck cannot see —exactly the class of thing this manifest exists to make visible, and the reason it
is excluded above rather than declared.
Listing it would red the job. Deleting it, if nothing reads it, is the other
resolution — but that is a separate call from adopting the manifest, so this issue
does not assume it.
Reconciling against the job
The failing
verifystep prints the manifest that run would justify — the setof git-tracked files the hooks actually wrote in CI. Treat that printout as the
oracle and the list above as a cross-check derived by reading the hooks. A
difference either way is information, not noise:
the file is generated by something the copy-artifacts job does not run.
(
forge buildis in there), or a generated file this reading missed.Undeclared-but-written paths are a printed note, never a failure — the check is
a subset assertion, not set equality — so a conservative first manifest is safe and
an over-eager one is not.
Adoption
One commit adding
script/codegen-manifest.txt. No workflow edit and noRAINIX_SHAbump: #392 wires the witness as a composite action resolved at@main, so nothing in this repo pins the check's version.Filed while tracking the org-wide adoption cost of rainlanguage/rainix#392. The
paths above were derived by reading this repo's own hooks and committed tree, not
by running the job.