Repository navigation
check: dist #95
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: 'check: dist' | |
| run-name: 'check: dist' | |
| # A `github-action` member ships THE REPO ITSELF at a git tag: the runner | |
| # checks out the tag and executes the committed `dist/` bundle, never `src/`. | |
| # So a `dist/` that does not match its sources ships a bundle silently missing | |
| # the change — the tag looks right and the code is old. | |
| # | |
| # This is the ONLY sound proof that the committed bundle matches `src/`. | |
| # The `committed-dist-is-current` check compares git commit ancestry, which can | |
| # prove STALENESS but never CURRENCY: one commit touching both `src/` and | |
| # `dist/` passes whether or not anyone rebuilt, as does a hand-edited `dist/`. | |
| # Rebuilding from a clean checkout and diffing is what settles it. | |
| # | |
| # Same shape GitHub uses for its own actions — actions/setup-node and | |
| # actions/checkout both run actions/reusable-workflows' check-dist.yml, which | |
| # installs, rebuilds, and fails on a non-empty diff, uploading the expected | |
| # bundle so the author can see what they should have committed. | |
| # PUSH, never pull_request. The fleet takes no outside contributions and | |
| # lands on main directly rather than through PRs, so a pull_request trigger | |
| # adds no coverage a push trigger does not already give — and it is the | |
| # fragile half: GitHub has narrowed pull_request defaults for security, and a | |
| # silently non-firing trigger reads as a green repo with no CI at all | |
| # (observed on sdxgen, 2026-08-06: no run was created for a clean PR). | |
| on: | |
| push: {} | |
| workflow_dispatch: {} | |
| permissions: | |
| contents: read | |
| # One rebuild per ref; an older run's verdict is worthless once new commits | |
| # land, so cancel it. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| check-dist: | |
| name: Check distribution | |
| runs-on: ubuntu-26.04 | |
| timeout-minutes: 20 | |
| env: | |
| # Socket Firewall + CLI auth for the sfw-wrapped setup + pnpm install — | |
| # sfw and socket-cli read SOCKET_API_KEY from the org-wide secret. | |
| SOCKET_API_KEY: ${{ secrets.SOCKET_API_TOKEN_FOR_CLI_AND_SFW }} | |
| steps: | |
| # First step can't call the local ./.github/actions/fleet/checkout | |
| # composite (nothing checked out yet); bootstrap the workspace with the | |
| # same inline git-fetch shape the other push-triggered workflows use. | |
| - name: Bootstrap checkout | |
| shell: bash | |
| env: | |
| GITHUB_TOKEN: ${{ github.token }} | |
| SERVER_URL: ${{ github.server_url }} | |
| REPOSITORY: ${{ github.repository }} | |
| TRIGGER_REF: ${{ github.sha }} | |
| run: | | |
| set -euo pipefail | |
| git init -q | |
| git config --local advice.detachedHead false | |
| git remote remove origin 2>/dev/null || true | |
| git remote add origin "${SERVER_URL}/${REPOSITORY}" | |
| FETCH_ARGS=(--no-tags --prune --depth 1 origin "${TRIGGER_REF}") | |
| if [ -n "${GITHUB_TOKEN}" ]; then | |
| AUTH_B64="$(printf 'x-access-token:%s' "${GITHUB_TOKEN}" | base64 | tr -d '\n')" | |
| export GIT_CONFIG_COUNT=1 | |
| export GIT_CONFIG_KEY_0="http.${SERVER_URL}/.extraheader" | |
| export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}" | |
| git fetch "${FETCH_ARGS[@]}" | |
| else | |
| git fetch "${FETCH_ARGS[@]}" | |
| fi | |
| git checkout -q --detach FETCH_HEAD | |
| - name: Set up and install | |
| uses: ./.github/actions/fleet/setup-and-install | |
| with: | |
| # Reuse the Release App for a contents:read token scoped to wheelhouse. | |
| # Both credentials enable the private release fallback. Without the | |
| # key, hydration still pulls public GHCR anonymously. | |
| payload-token-client-id: ${{ secrets.SOCKET_RELEASE_CLIENT_ID || vars.SOCKET_RELEASE_CLIENT_ID }} | |
| payload-token-private-key: ${{ secrets.SOCKET_RELEASE_APP_PRIVATE_KEY }} | |
| - name: Rebuild dist | |
| run: pnpm run build | |
| # `git status --porcelain` rather than `git diff`: a rebuild that emits a | |
| # NEW bundle file leaves it UNTRACKED, and `git diff` reports nothing for | |
| # an untracked path. That is a real miss — a new entrypoint would ship | |
| # absent from the tag while the gate stayed green. Porcelain reports | |
| # modified and untracked alike, and still ignores gitignored paths. | |
| - name: Compare the committed dist against the rebuild | |
| id: diff | |
| run: | | |
| changed="$(git status --porcelain -- dist)" | |
| if [ -n "$changed" ]; then | |
| echo "The committed dist/ does not match a clean rebuild of src/." | |
| echo "Run 'pnpm run build' and commit dist/ in the same change as its sources." | |
| echo | |
| echo "Changed paths:" | |
| echo "$changed" | |
| echo | |
| echo "Diff of tracked files:" | |
| git diff --ignore-space-at-eol -- dist | |
| exit 1 | |
| fi | |
| echo "dist/ matches a clean rebuild." | |
| # On failure the author gets the bundle they should have committed, so | |
| # fixing it is a download rather than a local toolchain reproduction. | |
| - name: Upload the expected dist | |
| if: ${{ failure() && steps.diff.conclusion == 'failure' }} | |
| uses: ./.github/actions/fleet/upload-artifact | |
| with: | |
| name: expected-dist | |
| path: dist/ |