Skip to content

chore: require Package.resolved to move with the contract pins - #978

Merged
bmc08gt merged 2 commits into
mainfrom
chore/pin-resolved-guard
Oct 5, 2026
Merged

bmc08gt merged 2 commits into
mainfrom
chore/pin-resolved-guard

Conversation

@bmc08gt

@bmc08gt bmc08gt commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

The flipcash2 pin in FlipcashAPI/Package.swift moved to 0.17.0 while the workspace Package.resolved still named 0.16.0, and it reached main through #974. The Package.resolved is current check failed on that PR, but it runs after the fact and admins can merge past it. Xcode Cloud resolves only from the committed file, so deploys break until #977 lands.

This makes the two files move together at commit time:

  • Scripts/git-hooks/pre-commit rejects a commit where a contract pin in the staged Package.swift doesn't match that package's version in the staged Package.resolved. It reads the pin-to-identity mapping from ContractPackage in Package.swift, compares text only (no network, no xcodebuild), and runs only when one of the two files is staged.
  • Scripts/bump-contract.sh <ocp|flipcash2> <version> is the way to bump. It refuses unless the tag exists on the client repo, edits the pin, resolves with FLIPCASH_PROTO_LOCAL and FLIPCASH_PROTO_LOCAL_PACKAGES unset for that call, aborts and restores both files if any other package's entry moved, and stages both. It also refuses to start if either file already has uncommitted changes. The resolve takes about 4.5 minutes and prints nothing until it finishes.
  • .claude/docs/technology-stack.md points the contract-bump instructions at the script.

The hook only runs in checkouts with core.hooksPath set to Scripts/git-hooks, which Scripts/build.sh does on first run. The CI check stays as the backstop for everything else.

Xcode Cloud resolves only from the committed Package.resolved and will
not update it, so a Package.swift pin that moved without it fails the
deploy. The CI check catches that after the commit lands; the pre-commit
hook now refuses it when either file is staged.

It parses the `case .<pkg>: return "X.Y.Z"` pins and the identity mapping
from the staged Package.swift and compares them with the staged
Package.resolved. Text only: no network, no xcodebuild.
…ge.resolved together

The pre-commit hook now rejects a pin that disagrees with Package.resolved;
this is the path that produces both changes in one step. It refuses unless
the version's tag exists on the client-protocol repo, edits the pin, resolves
with FLIPCASH_PROTO_LOCAL unset, aborts and restores both files if anything
besides that package's entry (and originHash) changed, then stages both.
@bmc08gt bmc08gt self-assigned this Oct 5, 2026
@bmc08gt
bmc08gt merged commit 3586156 into main Oct 5, 2026
2 of 3 checks passed
@bmc08gt
bmc08gt deleted the chore/pin-resolved-guard branch October 5, 2026 23:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant