Skip to content

fix(release): reproducible SDK probe receipt - #70

Closed
leoisadev1 wants to merge 1 commit into
mainfrom
leoplayz317/sdk-probe-repro
Closed

leoisadev1 wants to merge 1 commit into
mainfrom
leoplayz317/sdk-probe-repro

Conversation

@leoisadev1

@leoisadev1 leoisadev1 commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Summary

Linux dry run 37621664130 reproduced every package and all but one member of the source archive: third-party/linux-source-scope/remove-sdk-only-probe.json. It stores the stderr of a probe cargo build, including Compiling lines in parallel completion order and the Finished … in 2m 41s time. The receipt now drops Cargo's progress lines and keeps the exit code, warnings and errors.

Evidence

  • Run 37621664130: PASS rpm, AppImage, tarball, deb, source-audit; source archive 1 differing members: the probe receipt. Both manifests differ only because they hash the archive.

Merge Danger

Door: two-way.

Blast radius: one receipt in the source archive.

🤖 Generated with Claude Code


Devin Review

Linux dry run 37621664130 was byte-identical across both builds except for
third-party/linux-source-scope/remove-sdk-only-probe.json, which stored the
probe build's full stderr: Compiling lines in parallel completion order and
a wall-clock Finished time. The receipt keeps the exit code, warnings and
errors and drops Cargo's progress lines.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@leoisadev1 leoisadev1 closed this Oct 7, 2026
@leoisadev1
leoisadev1 deleted the leoplayz317/sdk-probe-repro branch October 7, 2026 14:46
@leoisadev1

Copy link
Copy Markdown
Member Author

Superseded by #69 (already on main as e6cfaa6), which drops the probe stderr field entirely for the same 37621664130 drift.

This branch conflicts with main on the same dump site. Closing to avoid a second round-trip; Build release linux 37639463182 is already queued on the #69 tip.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment on lines +264 to +266
'stderr': re.sub(r'^\s*(?:Compiling|Finished|Building|Fresh|Checking|Locking|Adding) .*\n?', '',
probe.stderr.replace(str(tree), '$SOURCE').replace(str(home), '$EMPTY_CARGO_HOME'),
flags=re.M)})

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Colored progress prevents reproducible source archives

With CARGO_TERM_COLOR=always, re.sub leaves ANSI-colored progress lines in the receipt. Their completion order and elapsed time vary, so identical source archives hash differently.

Learn more

Cargo can color stderr when CARGO_TERM_COLOR=always; the release workflow builds the archive twice and compares results. ANSI escapes before Compiling or Finished prevent the pattern from matching those lines. The unfiltered Finished duration and parallel progress order therefore continue to change the probe receipt between runs. The repository's colorized Cargo test documents that this environment occurs in GitHub Actions.

Example: With CARGO_TERM_COLOR=always, a line beginning \x1b[1m\x1b[32m Compiling survives the substitution; two builds with different completion orders write different receipts.

Recommended fix: Strip ANSI escape codes before filtering progress, or force CARGO_TERM_COLOR=never for the probe. Cover colored Compiling and Finished lines in a receipt-normalization test.

Devin Review


Was this helpful? React with 👍 or 👎 to provide feedback.

@greptile-apps

greptile-apps Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[Low risk] Adjusts build receipt logging for reproducibility.

The PR appears safe to merge; the missing receipt-filter test is a non-blocking improvement.

Fix All in Claude CodeFindings

  1. P2 Receipt filter lacks tests ▶

Summary

Removes Cargo progress lines from remove-sdk-only-probe.json to avoid differences caused by build order and elapsed time.

  • Keeps the build command, exit code, warnings, errors, and existing path replacements.
  • Add a focused regression test for the receipt filter.
  • No blocking defect was found. No build or runtime checks were run.

Reviews (1) · Last reviewed commit: "Keep Cargo progress lines out of the SDK..." · Reviewed by Greptile

Comment on lines +264 to +266
'stderr': re.sub(r'^\s*(?:Compiling|Finished|Building|Fresh|Checking|Locking|Adding) .*\n?', '',
probe.stderr.replace(str(tree), '$SOURCE').replace(str(home), '$EMPTY_CARGO_HOME'),
flags=re.M)})

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Receipt filter lacks tests

The new filter has no regression test. Existing tests cover derive_manifest and linux_target, not the saved stderr. Add a focused test showing that reordered Compiling lines and different Finished times produce identical output, while warnings and errors survive unchanged. This would catch another release mismatch without repeating a full build.

Correctness confidence: 5/5.

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

Fix in Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant