Repository navigation
feat(verify): report generated CLI provenance - #190
Conversation
Compile source provenance (kind, sanitized repository, pinned tag, resolved SHA, reproducibility) into generated modules and report it from `__lathe verify` and generated Skill references. Sync-state now records the sanitized repo_url and codegen rejects a state whose recorded repository differs from the configuration. Closes #123 Signed-off-by: samzong <samzong.lu@gmail.com>
Merging this PR will degrade performance by 44.35%
|
| Benchmark | BASE |
HEAD |
Efficiency | |
|---|---|---|---|---|
| ❌ | yaml |
2.5 ms | 5.3 ms | -52.61% |
| ❌ | BenchmarkParseNormalize |
3.6 ms | 6.9 ms | -47.11% |
| ❌ | json |
728 µs | 1,365.1 µs | -46.67% |
| ❌ | hit |
2 ms | 3.7 ms | -46.55% |
| ❌ | large |
829.6 µs | 1,536.5 µs | -46% |
| ❌ | large |
1.2 ms | 2.2 ms | -45.18% |
| ❌ | miss |
2 ms | 3.6 ms | -45.04% |
| ❌ | BenchmarkCatalogJSON |
1.6 ms | 2.9 ms | -44.93% |
| ❌ | BenchmarkBuildFlat |
1 ms | 1.8 ms | -44.47% |
| ❌ | BenchmarkFormatTableInferredColumns |
634.5 µs | 1,136.8 µs | -44.18% |
| ❌ | small |
62.8 µs | 111.9 µs | -43.89% |
| ❌ | small |
77.3 µs | 137.3 µs | -43.72% |
| ❌ | large |
872.1 µs | 1,547.8 µs | -43.65% |
| ❌ | large |
1.3 ms | 2.3 ms | -43.64% |
| ❌ | table |
416.3 µs | 730.8 µs | -43.04% |
| ❌ | BenchmarkFindCatalogCommand |
4.6 µs | 8 µs | -42.1% |
| ❌ | small |
104.2 µs | 179.8 µs | -42.04% |
| ❌ | yaml-large |
8.4 ms | 14.4 ms | -41.83% |
| ❌ | small |
79.2 µs | 135.2 µs | -41.37% |
| ❌ | json-small |
141.8 µs | 241 µs | -41.14% |
| ... | ... | ... | ... | ... |
ℹ️ Only the first 20 benchmarks are displayed. Go to the app to view all benchmarks.
Tip
Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.
Comparing feat/verify-provenance (673a57c) with main (0becbe5)
Summary
Closes #123.
MountModules:id,backend,kind(git/local), sanitizedrepo_url,pinned_tag,resolved_sha,reproducible.__lathe verify --jsonemits report version 2 withprovenance.cli,schema_version,catalog_schema_version, andsources; without--jsonit prints a human-readable summary.repo_urlis sanitized: HTTP user info, passwords, query, and fragment are stripped; SSH user names are kept; filesystem URLs are omitted.repo_url; codegen rejects a state whose recordedrepo_urldiffers from the configuration.repo_urland a resolved SHA are recorded and it has nogitproto dependency (those tags are not resolved to recorded SHAs). Local sources are never reproducible and never expose a path or SHA.Verification
make check— passed.go test -race ./internal/sourceconfig ./internal/specsync ./internal/codegen/render ./internal/lathecmd ./pkg/lathe ./pkg/runtime— passed.examples/petstoreandexamples/graphql:lathe codegen -cache fixtures, build,__lathe verify --json→ok: truewith provenance sources (kind: git,reproducible: true).local_pathbootstrap:kind: local,reproducible: false, no path in generated code or Skills.https://user:s3cret@...?token=abc: no secret ininternal/generatedorskills/; a changed repository fails codegen and echoes only the sanitized state URL.repo_url: codegen succeeds and reports repository unknown, not reproducible.Not verified:
examples/richapiend to end; proto sources with dependencies end to end (covered by unit test only).Compatibility
sourcesfor those binaries.runtime.SchemaVersionandruntime.CatalogSchemaVersionare unchanged.__lathe verifywithout--jsonnow prints text instead of JSON; all in-repo callers pass--json.repo_urland reportnot reproducibleuntillathe specsyncis re-run.Checklist
internal/generated/,.cache/, and ad-hocskills/<cli-name>/directories is not committed.