Skip to content

Migrate shared-file checksums to per-repo manifests - #47

Merged
bernardladenthin merged 10 commits into
mainfrom
claude/hopeful-pascal-9jlbqb
Oct 1, 2026
Merged

bernardladenthin merged 10 commits into
mainfrom
claude/hopeful-pascal-9jlbqb

Conversation

@bernardladenthin

Copy link
Copy Markdown
Owner

Replace the centralized checksum table in crossrepostatus.md with per-repository manifest files (.github/shared-files.sha256) and a shared-files CI job that validates them on every run.

Summary

This change decentralizes the maintenance of shared-file checksums from a single consolidated table to individual manifest files in each repository. The new approach:

  • Moves checksums from crossrepostatus.md into each repo's .github/shared-files.sha256
  • Introduces a shared-files CI job that runs check-shared-files.py to validate file integrity
  • Extends the job to also run check-versions.py (Maven dependency/plugin version consistency) and check-run-scripts.py (bash syntax validation)
  • Adds a release-gate check (check-release-gate.py) to ensure informational steps don't block releases
  • Replaces manual verification commands with automated checks that fail on drift within a single repo and warn when siblings diverge

Key Changes

  • crossrepostatus.md:

    • Removed the detailed checksum table with SHA-256 hashes and manual verification commands
    • Replaced with a reference table pointing to each repo's manifest file and its shared-files job
    • Updated the tool-versions row to note that check-versions.py now validates Maven dependency consistency
    • Clarified that the identity half (all four repos carry the same values) is now machine-checked
    • Updated references to shared files to point to manifests instead of the old table
  • policies/ci-test-diagnostics.md:

    • Replaced the inline crash-log printing script with a reference to the shared .github/print-crash-logs.sh
    • Updated to note that the script is now listed in each repo's shared-files.sha256 and checked by the shared-files job
    • Clarified that the script accepts module directories as arguments
  • policies/fat-jar-release-assets.md:

    • Updated references to shared files to use the new manifest-based approach
    • Changed instructions from "update the checksum table" to "run check-shared-files.py --write"
    • Updated the jllama smoke-test job description to reflect the matrix structure
    • Clarified srcmorph's classifier-based fat jar naming
  • policies/lombok-config.md:

    • Updated to reference the new per-repo manifest approach instead of the centralized checksum table
    • Changed sync instructions to use check-shared-files.py --write

Implementation Details

The new system uses manifest files (.github/shared-files.sha256) that list all shared files with their expected SHA-256 hashes. The shared-files CI job:

  • Fails if a file in the manifest has changed in the current repository
  • Warns if a sibling repository's default branch lists the same file with a different hash
  • Also validates Maven versions and bash script syntax as part of the same job
  • Enforces that informational steps in publish.yml don't gate the release process

This approach makes drift detection automatic and explicit, eliminating the need for manual checksum maintenance and verification commands.

https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2

jllama's all-<os>-<arch> jars are now plain merges of natives jars (no
jllama-backends.txt manifest), the natives jars are declared in
java-llama.cpp/.github/natives.csv, and srcmorph's classifier fat jars are the
CPU fat jar plus one backend.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
…sh table

The byte-identical files are now listed, with their SHA-256, in each repository's
.github/shared-files.sha256 and checked by its shared-files job (a copy changed alone fails, a
sibling's differing copy warns). crossrepostatus.md links those instead of carrying its own table
and manual sha256sum command, and records why copies with a checksum were chosen over a shared
actions repository. ci-test-diagnostics section 3 points at the shared print-crash-logs.sh; the
fat-jar and lombok policies point at the manifests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
…ions.py)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
… run scripts

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
… shared

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
…sitories

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
@bernardladenthin
bernardladenthin merged commit 5792c28 into main Oct 1, 2026
2 checks passed
@bernardladenthin
bernardladenthin deleted the claude/hopeful-pascal-9jlbqb branch October 1, 2026 10:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants