Skip to content

check: dist

check: dist #95

Workflow file for this run

name: 'check: dist'
run-name: 'check: dist'
# A `github-action` member ships THE REPO ITSELF at a git tag: the runner
# checks out the tag and executes the committed `dist/` bundle, never `src/`.
# So a `dist/` that does not match its sources ships a bundle silently missing
# the change — the tag looks right and the code is old.
#
# This is the ONLY sound proof that the committed bundle matches `src/`.
# The `committed-dist-is-current` check compares git commit ancestry, which can
# prove STALENESS but never CURRENCY: one commit touching both `src/` and
# `dist/` passes whether or not anyone rebuilt, as does a hand-edited `dist/`.
# Rebuilding from a clean checkout and diffing is what settles it.
#
# Same shape GitHub uses for its own actions — actions/setup-node and
# actions/checkout both run actions/reusable-workflows' check-dist.yml, which
# installs, rebuilds, and fails on a non-empty diff, uploading the expected
# bundle so the author can see what they should have committed.
# PUSH, never pull_request. The fleet takes no outside contributions and
# lands on main directly rather than through PRs, so a pull_request trigger
# adds no coverage a push trigger does not already give — and it is the
# fragile half: GitHub has narrowed pull_request defaults for security, and a
# silently non-firing trigger reads as a green repo with no CI at all
# (observed on sdxgen, 2026-08-06: no run was created for a clean PR).
on:
push: {}
workflow_dispatch: {}
permissions:
contents: read
# One rebuild per ref; an older run's verdict is worthless once new commits
# land, so cancel it.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
check-dist:
name: Check distribution
runs-on: ubuntu-26.04
timeout-minutes: 20
env:
# Socket Firewall + CLI auth for the sfw-wrapped setup + pnpm install —
# sfw and socket-cli read SOCKET_API_KEY from the org-wide secret.
SOCKET_API_KEY: ${{ secrets.SOCKET_API_TOKEN_FOR_CLI_AND_SFW }}
steps:
# First step can't call the local ./.github/actions/fleet/checkout
# composite (nothing checked out yet); bootstrap the workspace with the
# same inline git-fetch shape the other push-triggered workflows use.
- name: Bootstrap checkout
shell: bash
env:
GITHUB_TOKEN: ${{ github.token }}
SERVER_URL: ${{ github.server_url }}
REPOSITORY: ${{ github.repository }}
TRIGGER_REF: ${{ github.sha }}
run: |
set -euo pipefail
git init -q
git config --local advice.detachedHead false
git remote remove origin 2>/dev/null || true
git remote add origin "${SERVER_URL}/${REPOSITORY}"
FETCH_ARGS=(--no-tags --prune --depth 1 origin "${TRIGGER_REF}")
if [ -n "${GITHUB_TOKEN}" ]; then
AUTH_B64="$(printf 'x-access-token:%s' "${GITHUB_TOKEN}" | base64 | tr -d '\n')"
export GIT_CONFIG_COUNT=1
export GIT_CONFIG_KEY_0="http.${SERVER_URL}/.extraheader"
export GIT_CONFIG_VALUE_0="AUTHORIZATION: basic ${AUTH_B64}"
git fetch "${FETCH_ARGS[@]}"
else
git fetch "${FETCH_ARGS[@]}"
fi
git checkout -q --detach FETCH_HEAD
- name: Set up and install
uses: ./.github/actions/fleet/setup-and-install
with:
# Reuse the Release App for a contents:read token scoped to wheelhouse.
# Both credentials enable the private release fallback. Without the
# key, hydration still pulls public GHCR anonymously.
payload-token-client-id: ${{ secrets.SOCKET_RELEASE_CLIENT_ID || vars.SOCKET_RELEASE_CLIENT_ID }}
payload-token-private-key: ${{ secrets.SOCKET_RELEASE_APP_PRIVATE_KEY }}
- name: Rebuild dist
run: pnpm run build
# `git status --porcelain` rather than `git diff`: a rebuild that emits a
# NEW bundle file leaves it UNTRACKED, and `git diff` reports nothing for
# an untracked path. That is a real miss — a new entrypoint would ship
# absent from the tag while the gate stayed green. Porcelain reports
# modified and untracked alike, and still ignores gitignored paths.
- name: Compare the committed dist against the rebuild
id: diff
run: |
changed="$(git status --porcelain -- dist)"
if [ -n "$changed" ]; then
echo "The committed dist/ does not match a clean rebuild of src/."
echo "Run 'pnpm run build' and commit dist/ in the same change as its sources."
echo
echo "Changed paths:"
echo "$changed"
echo
echo "Diff of tracked files:"
git diff --ignore-space-at-eol -- dist
exit 1
fi
echo "dist/ matches a clean rebuild."
# On failure the author gets the bundle they should have committed, so
# fixing it is a download rather than a local toolchain reproduction.
- name: Upload the expected dist
if: ${{ failure() && steps.diff.conclusion == 'failure' }}
uses: ./.github/actions/fleet/upload-artifact
with:
name: expected-dist
path: dist/