Repository navigation
fix(release): reproducible SDK probe receipt - #70
leoisadev1 wants to merge 1 commit into
Conversation
Linux dry run 37621664130 was byte-identical across both builds except for third-party/linux-source-scope/remove-sdk-only-probe.json, which stored the probe build's full stderr: Compiling lines in parallel completion order and a wall-clock Finished time. The receipt keeps the exit code, warnings and errors and drops Cargo's progress lines. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
| 'stderr': re.sub(r'^\s*(?:Compiling|Finished|Building|Fresh|Checking|Locking|Adding) .*\n?', '', | ||
| probe.stderr.replace(str(tree), '$SOURCE').replace(str(home), '$EMPTY_CARGO_HOME'), | ||
| flags=re.M)}) |
There was a problem hiding this comment.
🔴 Colored progress prevents reproducible source archives
With CARGO_TERM_COLOR=always, re.sub leaves ANSI-colored progress lines in the receipt. Their completion order and elapsed time vary, so identical source archives hash differently.
Learn more
Cargo can color stderr when CARGO_TERM_COLOR=always; the release workflow builds the archive twice and compares results. ANSI escapes before Compiling or Finished prevent the pattern from matching those lines. The unfiltered Finished duration and parallel progress order therefore continue to change the probe receipt between runs. The repository's colorized Cargo test documents that this environment occurs in GitHub Actions.
Example: With CARGO_TERM_COLOR=always, a line beginning \x1b[1m\x1b[32m Compiling survives the substitution; two builds with different completion orders write different receipts.
Recommended fix: Strip ANSI escape codes before filtering progress, or force CARGO_TERM_COLOR=never for the probe. Cover colored Compiling and Finished lines in a receipt-normalization test.
Was this helpful? React with 👍 or 👎 to provide feedback.
|
| 'stderr': re.sub(r'^\s*(?:Compiling|Finished|Building|Fresh|Checking|Locking|Adding) .*\n?', '', | ||
| probe.stderr.replace(str(tree), '$SOURCE').replace(str(home), '$EMPTY_CARGO_HOME'), | ||
| flags=re.M)}) |
There was a problem hiding this comment.
The new filter has no regression test. Existing tests cover derive_manifest and linux_target, not the saved stderr. Add a focused test showing that reordered Compiling lines and different Finished times produce identical output, while warnings and errors survive unchanged. This would catch another release mismatch without repeating a full build.
Correctness confidence: 5/5.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
Summary
Linux dry run 37621664130 reproduced every package and all but one member of the source archive:
third-party/linux-source-scope/remove-sdk-only-probe.json. It stores the stderr of a probecargo build, includingCompilinglines in parallel completion order and theFinished … in 2m 41stime. The receipt now drops Cargo's progress lines and keeps the exit code, warnings and errors.Evidence
1 differing members: the probe receipt. Both manifests differ only because they hash the archive.Merge Danger
Door: two-way.
Blast radius: one receipt in the source archive.
🤖 Generated with Claude Code