What changes, and when
rainlanguage/rainix#392 adds a
codegen witness to the rainix-copy-artifacts reusable workflow. This repo's
.github/workflows/git-clean.yaml calls that workflow at @main, so the check
arrives the moment #392 merges — not when this repo chooses to adopt it. The
next push after that merge fails until a manifest is committed.
Why the check exists
rainix-copy-artifacts currency-checks committed generated sources by re-running
the codegen hooks and then git diff --exit-code. That proves the committed
content is current, but it is structurally blind to a generator that has
stopped emitting a file: the committed copy is already correct, so nothing is
rewritten, nothing differs, and the job is green over a dead emitter. Reproduced
with a control in
rainlanguage/rain.factory.deploy#35.
Seeing that needs an independent statement of which committed files are
generated. That is script/codegen-manifest.txt: one repo-relative path per line,
# comments and blank lines ignored. The witness marks every git-tracked file's
mtime before the first hook and verifys after the last, calling a file
written when it exists and its mtime moved. Any declared path nothing wrote
fails the job by name.
Why this repo is affected
Hooks present: script/Build.sol, script/build.sh. No
script/codegen-manifest.txt today.
What to add
script/codegen-manifest.txt:
meta/FlareFtsoSubParserAuthoringMeta.rain.meta
meta/FlareFtsoWords.rain.meta
src/generated/FlareFtsoWordsPointers.sol
How that was derived
script/build.sh is nix develop -c rain-flare-prelude, and that task's body
in flake.nix runs forge script ./script/BuildAuthoringMeta.sol (writing
meta/FlareFtsoSubParserAuthoringMeta.rain.meta), then
rain meta build ... -o meta/FlareFtsoWords.rain.meta, then
forge script ./script/Build.sol and forge fmt.
script/Build.sol calls
LibFs.buildFileForContract(vm, ..., "FlareFtsoWordsPointers", ...) →
src/generated/FlareFtsoWordsPointers.sol.
Those three paths are the whole of meta/ and src/generated/ as committed today.
One ordering note specific to this repo
The prelude ends with its own forge fmt, which runs inside the witness window
(the verify step sits after the last hook and before the workflow's forge fmt).
That cannot cause a false red — fmt only adds writes, and undeclared writes are a
note, not a failure — but it does mean this repo's printout may list files that fmt
touched rather than a generator. Take the list above as the filter on it.
Reconciling against the job
The failing verify step prints the manifest that run would justify — the set
of git-tracked files the hooks actually wrote in CI. Treat that printout as the
oracle and the list above as a cross-check derived by reading the hooks. A
difference either way is information, not noise:
- listed above, absent from the printout — that emitter may already be dead, or
the file is generated by something the copy-artifacts job does not run.
- printed, absent from above — an incidental write inside the witness window
(forge build is in there), or a generated file this reading missed.
Undeclared-but-written paths are a printed note, never a failure — the check is
a subset assertion, not set equality — so a conservative first manifest is safe and
an over-eager one is not.
Adoption
One commit adding script/codegen-manifest.txt. No workflow edit and no
RAINIX_SHA bump: #392 wires the witness as a composite action resolved at
@main, so nothing in this repo pins the check's version.
Filed while tracking the org-wide adoption cost of rainlanguage/rainix#392. The
paths above were derived by reading this repo's own hooks and committed tree, not
by running the job.
What changes, and when
rainlanguage/rainix#392 adds a
codegen witness to the
rainix-copy-artifactsreusable workflow. This repo's.github/workflows/git-clean.yamlcalls that workflow at@main, so the checkarrives the moment #392 merges — not when this repo chooses to adopt it. The
next push after that merge fails until a manifest is committed.
Why the check exists
rainix-copy-artifactscurrency-checks committed generated sources by re-runningthe codegen hooks and then
git diff --exit-code. That proves the committedcontent is current, but it is structurally blind to a generator that has
stopped emitting a file: the committed copy is already correct, so nothing is
rewritten, nothing differs, and the job is green over a dead emitter. Reproduced
with a control in
rainlanguage/rain.factory.deploy#35.
Seeing that needs an independent statement of which committed files are
generated. That is
script/codegen-manifest.txt: one repo-relative path per line,#comments and blank lines ignored. The witnessmarks every git-tracked file'smtime before the first hook and
verifys after the last, calling a filewritten when it exists and its mtime moved. Any declared path nothing wrote
fails the job by name.
Why this repo is affected
Hooks present:
script/Build.sol,script/build.sh. Noscript/codegen-manifest.txttoday.What to add
script/codegen-manifest.txt:How that was derived
script/build.shisnix develop -c rain-flare-prelude, and that task's bodyin
flake.nixrunsforge script ./script/BuildAuthoringMeta.sol(writingmeta/FlareFtsoSubParserAuthoringMeta.rain.meta), thenrain meta build ... -o meta/FlareFtsoWords.rain.meta, thenforge script ./script/Build.solandforge fmt.script/Build.solcallsLibFs.buildFileForContract(vm, ..., "FlareFtsoWordsPointers", ...)→src/generated/FlareFtsoWordsPointers.sol.Those three paths are the whole of
meta/andsrc/generated/as committed today.One ordering note specific to this repo
The prelude ends with its own
forge fmt, which runs inside the witness window(the
verifystep sits after the last hook and before the workflow'sforge fmt).That cannot cause a false red — fmt only adds writes, and undeclared writes are a
note, not a failure — but it does mean this repo's printout may list files that fmt
touched rather than a generator. Take the list above as the filter on it.
Reconciling against the job
The failing
verifystep prints the manifest that run would justify — the setof git-tracked files the hooks actually wrote in CI. Treat that printout as the
oracle and the list above as a cross-check derived by reading the hooks. A
difference either way is information, not noise:
the file is generated by something the copy-artifacts job does not run.
(
forge buildis in there), or a generated file this reading missed.Undeclared-but-written paths are a printed note, never a failure — the check is
a subset assertion, not set equality — so a conservative first manifest is safe and
an over-eager one is not.
Adoption
One commit adding
script/codegen-manifest.txt. No workflow edit and noRAINIX_SHAbump: #392 wires the witness as a composite action resolved at@main, so nothing in this repo pins the check's version.Filed while tracking the org-wide adoption cost of rainlanguage/rainix#392. The
paths above were derived by reading this repo's own hooks and committed tree, not
by running the job.