Ship a per-release surface manifest with stable ids and refusal codes

- packages/compiler/surface-manifest.json is generated (pnpm manifest), committed, and shipped in @scriptc/compiler; entries project mechanically from the diagnostics registry, the unsupported-syntax dispatch tables, the stdlib/builtin lowering tables, and the supported-builtin-module list
- every non-static entry carries the SC code the compiler raises for it, and the version spine is the exact published release version
- FENCE_CODES joins the diagnostics registry so factory-minted construct fences are enumerable
- the sampling harness compiles listed-static probes and asserts each sampled non-static entry refuses with exactly its listed code, beside a byte-identical staleness guard
- the release workflow regenerates the manifest, fails on drift, and attaches it to the GitHub release
This commit is contained in:
Chris Tate
2026-07-22 22:01:45 -05:00
parent 235709a53d
commit d66c36b020
11 changed files with 2728 additions and 12 deletions
+34 -7
View File
@@ -138,23 +138,46 @@ jobs:
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# The GitHub release is a tag and notes only — scriptc has no platform
# binary assets to stage (programs compile on the user's machine) — so
# it runs AFTER a successful npm publish and never gates it. The body is
# the CHANGELOG.md block between the release:start/release:end markers,
# which RELEASING.md keeps on the latest entry only.
# The GitHub release is a tag, notes, and one asset: the surface
# manifest (packages/compiler/surface-manifest.json — the machine-
# readable listing of the surface the static tier compiles at this
# version, regenerated here and verified against the committed file).
# scriptc has no platform binary assets to stage (programs compile on
# the user's machine), so the job runs AFTER a successful npm publish
# and never gates it. The body is the CHANGELOG.md block between the
# release:start/release:end markers, which RELEASING.md keeps on the
# latest entry only.
github-release:
name: Create GitHub Release
needs: [check-release, publish]
if: needs.check-release.outputs.should_release == 'true'
runs-on: ubuntu-latest
timeout-minutes: 5
timeout-minutes: 10
permissions:
contents: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Setup pnpm
uses: pnpm/action-setup@v4
with:
version: 11
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: "24"
# Regenerate the surface manifest from this tree and require it to
# match the committed file byte-for-byte — the same staleness guard
# the test suite runs — so the attached asset is provably the
# manifest of the code being released.
- name: Generate surface manifest
run: |
pnpm install --frozen-lockfile
pnpm manifest --check
- name: Extract changelog entry
run: |
VERSION="${{ needs.check-release.outputs.version }}"
@@ -173,7 +196,7 @@ jobs:
TAG="v$VERSION"
if gh release view "$TAG" &>/dev/null; then
echo "Release $TAG already exists, skipping"
echo "Release $TAG already exists, skipping creation"
else
echo "Creating release $TAG..."
gh release create "$TAG" \
@@ -181,5 +204,9 @@ jobs:
--title "$TAG" \
--notes-file /tmp/release-notes.md
fi
# Attach the surface manifest (idempotent: --clobber makes
# re-runs replace the asset instead of failing).
gh release upload "$TAG" packages/compiler/surface-manifest.json --clobber
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}