Skip to content

feat(verify): report generated CLI provenance - #190

Merged
samzong merged 1 commit into
mainfrom
feat/verify-provenance
Oct 3, 2026
Merged

samzong merged 1 commit into
mainfrom
feat/verify-provenance

Conversation

@samzong

@samzong samzong commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

Summary

Closes #123.

  • Codegen compiles per-source provenance into MountModules: id, backend, kind (git/local), sanitized repo_url, pinned_tag, resolved_sha, reproducible.
  • __lathe verify --json emits report version 2 with provenance.cli, schema_version, catalog_schema_version, and sources; without --json it prints a human-readable summary.
  • Generated Skill references show source kind, repository, pinned tag, resolved SHA, and reproducibility.
  • repo_url is sanitized: HTTP user info, passwords, query, and fragment are stripped; SSH user names are kept; filesystem URLs are omitted.
  • Sync-state records the sanitized repo_url; codegen rejects a state whose recorded repo_url differs from the configuration.
  • A git source is reproducible only when a public repo_url and a resolved SHA are recorded and it has no git proto dependency (those tags are not resolved to recorded SHAs). Local sources are never reproducible and never expose a path or SHA.

Verification

  • make check — passed.
  • go test -race ./internal/sourceconfig ./internal/specsync ./internal/codegen/render ./internal/lathecmd ./pkg/lathe ./pkg/runtime — passed.
  • examples/petstore and examples/graphql: lathe codegen -cache fixtures, build, __lathe verify --json → ok: true with provenance sources (kind: git, reproducible: true).
  • Scratch local_path bootstrap: kind: local, reproducible: false, no path in generated code or Skills.
  • Credential URL https://user:s3cret@...?token=abc: no secret in internal/generated or skills/; a changed repository fails codegen and echoes only the sanitized state URL.
  • Legacy sync-state without repo_url: codegen succeeds and reports repository unknown, not reproducible.

Not verified: examples/richapi end to end; proto sources with dependencies end to end (covered by unit test only).

Compatibility

  • Generated code from earlier releases still mounts; verify reports empty sources for those binaries. runtime.SchemaVersion and runtime.CatalogSchemaVersion are unchanged.
  • __lathe verify without --json now prints text instead of JSON; all in-repo callers pass --json.
  • Existing sync-states lack repo_url and report not reproducible until lathe specsync is re-run.
  • Proto dependency identities are not part of provenance.

Checklist

  • Tests or focused verification cover the changed surface.
  • User-facing behavior changes are documented.
  • Generated output under internal/generated/, .cache/, and ad-hoc skills/<cli-name>/ directories is not committed.
  • Commits are signed off when this is ready to merge.

Compile source provenance (kind, sanitized repository, pinned tag,
resolved SHA, reproducibility) into generated modules and report it
from `__lathe verify` and generated Skill references. Sync-state now
records the sanitized repo_url and codegen rejects a state whose
recorded repository differs from the configuration.

Closes #123

Signed-off-by: samzong <samzong.lu@gmail.com>
@ghfind-review ghfind-review Bot added the review: top ghfind author score; see https://ghfind.com label Oct 3, 2026
@codspeed

codspeed Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Merging this PR will degrade performance by 44.35%

⚠️ Unknown Walltime execution environment detected

Using the Walltime instrument on standard Hosted Runners will lead to inconsistent data.

For the most accurate results, we recommend using CodSpeed Macro Runners: bare-metal machines fine-tuned for performance measurement consistency.

⚠️ Different runtime environments detected

Some benchmarks with significant performance changes were compared across different runtime environments,
which may affect the accuracy of the results.

Open the report in CodSpeed to investigate

❌ 21 regressed benchmarks

Warning

Please fix the performance issues or acknowledge them on CodSpeed.

Performance Changes

Benchmark BASE HEAD Efficiency
❌ yaml 2.5 ms 5.3 ms -52.61%
❌ BenchmarkParseNormalize 3.6 ms 6.9 ms -47.11%
❌ json 728 µs 1,365.1 µs -46.67%
❌ hit 2 ms 3.7 ms -46.55%
❌ large 829.6 µs 1,536.5 µs -46%
❌ large 1.2 ms 2.2 ms -45.18%
❌ miss 2 ms 3.6 ms -45.04%
❌ BenchmarkCatalogJSON 1.6 ms 2.9 ms -44.93%
❌ BenchmarkBuildFlat 1 ms 1.8 ms -44.47%
❌ BenchmarkFormatTableInferredColumns 634.5 µs 1,136.8 µs -44.18%
❌ small 62.8 µs 111.9 µs -43.89%
❌ small 77.3 µs 137.3 µs -43.72%
❌ large 872.1 µs 1,547.8 µs -43.65%
❌ large 1.3 ms 2.3 ms -43.64%
❌ table 416.3 µs 730.8 µs -43.04%
❌ BenchmarkFindCatalogCommand 4.6 µs 8 µs -42.1%
❌ small 104.2 µs 179.8 µs -42.04%
❌ yaml-large 8.4 ms 14.4 ms -41.83%
❌ small 79.2 µs 135.2 µs -41.37%
❌ json-small 141.8 µs 241 µs -41.14%
... ... ... ... ...

ℹ️ Only the first 20 benchmarks are displayed. Go to the app to view all benchmarks.

Tip

Investigate this regression by commenting @codspeedbot fix this regression on this PR, or directly use the CodSpeed MCP with your agent.


Comparing feat/verify-provenance (673a57c) with main (0becbe5)

Open in CodSpeed

@samzong
samzong marked this pull request as ready for review October 3, 2026 18:54
@samzong
samzong merged commit adcb3f1 into main Oct 3, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

review: top ghfind author score; see https://ghfind.com

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(verify): report generated CLI provenance

1 participant