Skip to content

feat: expose the package version and proto pin at runtime - #7

Merged
bmc08gt merged 6 commits into
mainfrom
feat/contract-info
Sep 16, 2026
Merged

bmc08gt merged 6 commits into
mainfrom
feat/contract-info

Conversation

@bmc08gt

@bmc08gt bmc08gt commented Sep 16, 2026

Copy link
Copy Markdown
Collaborator

The published artifact is entirely generated protobuf, so nothing in it says which
contract it holds. An app consuming it can read its own pinned version out of a build
file, but the upstream commit that version was generated from only exists in this repo's
lock file — and a build on a local proto sync is indistinguishable from a pinned one.

Both generated clients now carry VERSION/version and PROTO_COMMIT/protoCommit,
with shortProtoCommit defining the display truncation once so both platforms agree, and
isLocal for the sync-protos.sh --local case.

The Kotlin side is a Gradle task writing into build/, never committed. The Swift side is
appended to generate-swift.sh, which already wipes Sources/ before generating — anything
committed there has to be produced by that script or it vanishes on the next run.

ContractInfo.swift is excluded from the git diff -- Sources codegen check, because
publish.yml now stamps the released version into the commit it tags and that check would
read the stamp as drift. scripts/check-contract-info.sh guards the field that actually
matters — the commit — and CI runs it on both languages.

The release stamp commit is not pushed to main; only the tag is. main keeps -dev.

The published artifact is all generated protobuf, so a consumer has no way to read
which contract it holds. generateContractInfo writes an OcpContractInfo object into
the main source set carrying the Gradle version and the commit ocp.lock is pinned at.

A local sync writes 'commit: LOCAL', so a composite-build consumer gets isLocal for
free rather than needing a second signal.
SPM ships source, so the Swift side needs the same metadata committed rather than
computed at build time. generate-swift.sh owns it because that script wipes
Sources/OCPClientProtocol before generating -- anything sync-protos.sh wrote there
would not survive a regenerate.

Off a release the version is the next CHANGELOG heading plus -dev. publish.yml re-runs
this with RELEASE_VERSION set and commits the result onto the tag, so main keeps -dev.
The Kotlin job regenerates the metadata object and asserts both sides carry the commit
ocp.lock names. Sources/OCPClientProtocol/ContractInfo.swift is committed, so this runs
on ubuntu without the Swift toolchain.

The Swift codegen equality check excludes ContractInfo.swift. publish.yml stamps its
version line just before tagging, so on a released tag it will not match what codegen
produces from CHANGELOG.md; the commit field is the part that matters and the new check
guards it.
…e tagging

On main ContractInfo.swift reads '<next>-dev', because the version is not real until
this workflow runs. Between the Central upload and the tag, regenerate it with the real
number and commit, so the tag -- which is the Swift release -- carries a released version.

The commit is not pushed to a branch. Only the tag is, so main keeps -dev and the
workflow needs no write access to a protected branch; the stamped commit stays reachable
from the tag, which is what SPM resolves. The cost is that git log main does not show
release commits, and the tags are the record.
ContractInfo.swift moves to 0.5.0-dev because its version is derived from the top
CHANGELOG heading, which this commit adds.
@bmc08gt bmc08gt self-assigned this Sep 16, 2026
@bmc08gt
bmc08gt merged commit 066e584 into main Sep 16, 2026
3 checks passed
@bmc08gt
bmc08gt deleted the feat/contract-info branch September 16, 2026 20:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant