Commit Graph
132 Commits
Author SHA1 Message Date
Abdessamad Derraz 232ef1a6b8 fix: let the constrained declaration win in manifests too
A destination can be declared by more than one system, bare in one and
hash-constrained in another. generate_pack resolves that with
_preferred_entries so the constrained sibling claims the destination;
generate_manifest never did, and named whatever answered to the name.

RetroDECK's bios/d2fdc.zip is the case: declared with an md5 in the
arcade system and bare under apple-ii. The pack carried the right
archive, 262 bytes reached through the MAME clone map, while the
manifest sent install.py to a 256-byte Apple II ROM. Downloading the
ZIP and running the installer gave different files.

A test now hashes every manifest entry a platform pins and compares it
against what the platform declares: 3295 entries, on the platforms whose
frontend reads the bytes. It accepts any of several declarations for one
destination, the member-composite MD5 Recalbox pins for arcade archives,
and Batocera's 29-character prefixes. Reinstating the old manifest entry
fails it.
2026-08-23 12:14:56 +02:00
Abdessamad Derraz 8b404e500f fix: keep a packed file's executable bit
Pinning every member's metadata made packs reproducible and took the
executable bit with it. The RetroDECK pack ships the two Voxatron engine
binaries, and extracted at 644 they cannot be run.

Git records the bit, so reading it from the source file keeps a pack the
same from any clone. Nothing else about the source's mode reaches the
archive: 2569 members ship at 644 and 942 at 755, which is what the
builder produced before the pinning.

Nothing caught this. The comparison that proved the pinning inert
checked member names, CRCs and sizes, and mode is none of those. A test
now builds a runnable payload and asserts it survives extraction.

RetroDECK rebuilds to the same bytes twice and passes its integrity
check, 2008/2008 baseline and 1551/1551 cores.
2026-08-23 07:58:23 +02:00
Abdessamad Derraz 593b277bc4 refactor: one place decides which profiles answer
The verifier and the builder each resolved the profiles a run names, in
thirty-five lines that differed only in how they failed: one exits, the
other returns empty-handed. An alias is the same binary under another
name and a launcher only starts an emulator, so neither has requirements
of its own, and both refusals have to say the same thing.

common raises now and each caller chooses its own ending. Six tests hold
the refusals, one of them reading both sources so a copy cannot grow
back. The manifest's core-complement phase comes out of generate_manifest
in the same pass, 60 to 34.

Verified inert: manifests identical entry for entry, and the Handy pack
rebuilds to the same bytes.
2026-08-23 07:18:41 +02:00
Abdessamad Derraz c313b32347 chore: neutral report path and plain punctuation
The markdown report wrote to a directory named after the tooling that
happened to produce it. It takes --report-dir now, defaulting to
reports/, so nothing in the tree names anything but the project.

Em-dashes replaced throughout the sources and tests, rephrased rather
than swapped for a comma where the dash carried an apposition.
2026-08-12 16:16:52 +02:00
Abdessamad Derraz d2cc806e76 refactor: name the pack builder's decisions
Two decisions taken before a byte is written come out of generate_pack.
Which declaration wins when several claim one destination: a platform
may declare the same file bare in one system and hash-constrained in
another, and first-come dedup would let the bare one pack whatever
answers to the name. And which regional or slot alternatives the pack
leaves out, decided once over the baseline and the core extras together.

Complexity 170 to 142. The Recalbox pack rebuilds to the same bytes as
before the change, and the manifests and site are unchanged on frozen
inputs.
2026-08-12 16:14:25 +02:00
Abdessamad Derraz a2bd197b9b fix: pin every pack member to a fixed date
A pack was still not a function of its inputs. ZipFile.write copies the
source file's mtime into the member: the wall clock for an archive this
build rebuilt in tmp/, the checkout time for a file from the collection.
Two consecutive builds of the Recalbox pack differed on 348 members
whose content matched byte for byte, and a pack built from a fresh clone
could never match one built from another.

Every member now goes through one writer that stamps the epoch the
archive rebuilder already uses, streaming the content so a firmware
image of several hundred megabytes is not read whole.

The pack was already covered by a two-builds-are-identical test, which
passed: its fixture held no romset, so it never reached the rebuild
path. The fixture has one now, and reverting the writer fails both that
test and the new one.

Verified on the real collection: Recalbox and RetroArch rebuild to the
same bytes twice, contents unchanged from the previous revision (1319
and 4517 members, zero CRC differences), and both still pass their
native integrity check.
2026-08-12 15:14:48 +02:00
Abdessamad Derraz c31ce0b693 refactor: split the pack builder into its layers
generate_pack.py held six responsibilities in 4744 lines. Five move out
in dependency order, so nothing above reaches back down: destinations,
core extras, resolution with its storage tiers, the notes shipped inside
a pack, and the pack verifier. generate_pack.py keeps the build and the
command line, and re-exports the rest.

Two things the move surfaced. The offline switch was a module global the
command line assigned, which a re-export would have copied and frozen at
False; it is set through a call now and not re-exported. And a facade
placed after the entry point binds too late: importing the module worked,
running it did not, so the manifest run died on a name the tests never
exercised because tests import.

Verified against the previous revision on frozen inputs: every generated
artefact is identical, save the catalogue that embeds hashes of files
carrying a build timestamp.
2026-08-12 12:20:17 +02:00
Abdessamad Derraz 5e168b86c8 refactor: ask the mode module instead of retyping it
Four sites still compared the verification mode to a literal after the
module owning that policy existed. One of them mattered: an unrecognised
mode fell through to MD5 verification while compute_severity was scoring
it as existence, so a typo in a platform YAML produced a report whose
checks and severities described different platforms.

The mode is normalized once per run and the consumers ask for what they
need. A test reads the sources and fails on a literal comparison, so the
next consumer cannot quietly grow a fifth copy.
2026-08-12 07:36:29 +02:00
Abdessamad Derraz b11c8b0638 fix: keep the agnostic scan inside its own tree
A filename-agnostic core accepts any name for its BIOS, so the builder
scans the directory holding the candidates. It picked that directory
from a first-hit lookup by name, the one piece of evidence that lands
in another emulator's tree: five files answer to GameIndex.yaml and one
belongs to an Android package, rom1.bin is a PS2 ROM and a Roland
SC-55 ROM. One wrong match became every file beside it, flattened into
the BIOS root of platforms that do not run that emulator: 45 files in
the Recalbox pack, 170 in the RetroArch one.

Four things decide it now. A destination and the repo layout meet on a
tail, so the path index is tried from the longest tail down and never
to the bare filename; that alone corrects seven files, among them the
Japanese GameCube slot, which held the US dump. A seed has to declare
the shape it is looking for, since no shape means the whole directory.
An ambiguous name needs the profile's other files to agree before the
scan walks anywhere. What the scan emits carries the SHA-1 it selected,
so packing never resolves it by name again.
2026-08-12 07:23:23 +02:00
Abdessamad Derraz b33d045175 fix: group region candidates once for both sides
The builder and the coverage report each grouped their own candidates
before asking which regional alternatives to withdraw. The builder
grouped the platform files and the core extras; the report grouped the
platform files alone, and keyed them on an unsanitized destination.

So a region run withdrew 73 files from a recalbox pack while the report
withdrew 14, and described the other 59 as covered by a pack that would
not carry them.

platform_region_groups builds the grouping once and both sides read it.
The extras it returns are keyed by emulator, name and path: Dolphin
declares three IPL.bin that differ by path alone, and a name-keyed map
withdraws the wrong one. Manifests are byte-identical before and after.
2026-08-12 06:43:47 +02:00
Abdessamad Derraz 34619c778f fix: publish target aliases and refuse an unknown one
The pack builder accepts the aliases declared in the target overrides,
so --target switch works there, but the installer's target manifests
carried only canonical names. The documented word was the one that
failed, and the installer then carried on with every file: 1911 files
and 4.1 GB where the user had asked for the 863 that target needs.

Aliases are emitted beside their canonical target, and an unknown
target now stops the run and lists what is available. A filter is
applied or refused, never ignored.
2026-08-12 06:13:21 +02:00
Abdessamad Derraz 36a284b93b fix: name and announce every narrowed pack 2026-08-11 17:54:28 +02:00
Abdessamad Derraz 4bd277a7be feat: name every narrowing in the pack filename 2026-08-11 16:56:20 +02:00
Abdessamad Derraz 694f2a74d0 fix: index emulator systems by display name too 2026-08-11 15:56:45 +02:00
Abdessamad Derraz 94512b5acf fix: drop manifest entries with no download source
install.py fetches a file from its repo_path or from a release asset.
Resolution can land on a file the database does not index, and the
entry then shipped with neither: a line in the download list that can
only ever fail. Those are recorded as omitted instead, which is what
the installer already knows how to report, and a test holds the
committed manifests to it.

validate_schemas read dist/ while a build was writing it and reported
a half-written pack as 'File is not a zip file'. It takes the shared
lock --verify-packs uses, and says so when a build holds it.
2026-08-11 14:40:33 +02:00
Abdessamad Derraz a372f2abf3 feat: keep one bios per slot on declared order 2026-08-11 13:34:15 +02:00
Abdessamad Derraz ecbe69760d refactor: check packs through a single path 2026-08-11 11:31:21 +02:00
Abdessamad Derraz d8e4325af2 fix: skip conformance on required-only packs
A required-only build is narrower than the platform declares by
design, like the source-restricted variants already handled, so the
full expectation must not be applied to it. --region is also refused
alongside --manifest-targets, which carries no region dimension.
2026-08-11 05:34:21 +02:00
Abdessamad Derraz 24e9b820ae feat: make packs reproducible byte for byte
Two builds of the same pack from the same inputs produced different
archives. Of 67 members, 65 were already identical: only README.txt
and manifest.json differed, both stamped with the wall clock by
writestr and the second carrying a generated timestamp. Generated
members now use the epoch the archive rebuilder already applies, and
the timestamp comes from the database snapshot the pack was built
from, so the same data yields the same bytes.

Install manifests skipped archived platforms, which is why RetroPie
had none; archived means upstream is no longer scraped, not that the
packs stopped shipping. A target-filtered manifest also had no record
of its filter beyond the filename, so it carries one the way a
region-filtered manifest already does.
2026-08-11 00:55:42 +02:00
Abdessamad Derraz e8ee8b0954 fix: decide hash mismatch by native mode
A declared hash that the local dump contradicts is not one situation. An
existence platform never reads the bytes, so withholding the file lets an
upstream list error remove something the frontend would have loaded; a
hash platform would reject it, so shipping it is pointless.

The mode now decides, at every point that had an opinion: pack building,
core complement, emulator packs, manifests, conformance and
_intentional_hash_exclusion. verify.find_undeclared_files follows, since
verify and generate_pack must agree file for file.

Also here: resolution reports which evidence matched rather than a flat
"exact", a path or filename can no longer override a declared hash, and
safe_extract_zip treats a Windows backslash as the separator it is
instead of refusing the archive.
2026-08-10 13:36:03 +02:00
Abdessamad Derraz 45f89cc6c0 feat: add region filters and profiles 2026-08-09 14:15:56 +02:00
Abdessamad Derraz eb2c064518 fix: create scratch dir and scope catalog ratio 2026-08-08 11:05:23 +02:00
Abdessamad Derraz 25f8537a4a fix: point manifest entries at a fetchable file 2026-08-08 06:19:38 +02:00
Abdessamad Derraz 45dbc30301 feat: lock pack artifacts during pipeline runs 2026-08-08 04:24:03 +02:00
Abdessamad Derraz 76fbade6b8 fix: resolve archives with profile hashes 2026-08-07 19:04:33 +02:00
Abdessamad Derraz 8bd2083e80 feat: report hash proof in existence packs 2026-08-07 16:23:15 +02:00
Abdessamad Derraz 3ecb72d275 fix: deflate manifest on zip append path 2026-08-07 15:45:48 +02:00
Abdessamad Derraz 792bad3fd5 fix: align pack checks with builder, purge stale packs 2026-08-06 16:41:47 +02:00
Abdessamad Derraz 36b9b59e2e fix: match pack zips to declared platform hashes 2026-08-06 05:00:50 +02:00
Abdessamad Derraz 8f93ee2239 feat: flatten zips, standalone copies, retropie grouping 2026-04-03 12:04:55 +02:00
Abdessamad Derraz 9ba8b02ff1 fix: verify functions handle flat zip extraction 2026-04-03 11:50:26 +02:00
Abdessamad Derraz 76a3543672 feat: verify functions handle flat and nested ZIPs 2026-04-03 11:15:32 +02:00
Abdessamad Derraz 48d185dd7d feat: flatten ZIP structure, strip base_dest prefix 2026-04-03 11:12:14 +02:00
Abdessamad Derraz 97e26103f5 fix: include source/req tags in grouped pack rename 2026-04-03 11:07:34 +02:00
Abdessamad Derraz 5ee81b30c6 feat: add contributor credits to pack readme 2026-04-02 11:43:06 +02:00
Abdessamad Derraz 0401d058a1 feat: add by_sha256 index, fix reporting attribution
generate_db: add by_sha256 index for O(1) variant lookup.
verify: _find_best_variant uses indexed sha256 instead of O(n) scan.
validation: check_file_validation returns (reason, emulators) tuple,
attributing mismatch only to emulators whose check actually failed.
beetle_psx: remove incorrect size field for ps1_rom.bin (code does
not validate size, swanstation is sole size authority).
2026-04-02 00:59:01 +02:00
Abdessamad Derraz 9bbd39369d fix: alias-only files missing from full packs
find_undeclared_files was enriching declared_names with DB aliases,
filtering core extras that were never packed by Phase 1 under that
name. Pass strict YAML names to _collect_emulator_extras so alias-
only files (dc_bios.bin, amiga-os-310-a1200.rom, scph102.bin, etc.)
get packed at the emulator's expected path. Also fix truth mode
output message and --all-variants --verify-packs quick-exit bypass.
2026-04-01 18:39:36 +02:00
Abdessamad Derraz a1333137a0 fix: truth mode skipping phases 2-3 due to indent 2026-04-01 15:12:45 +02:00
Abdessamad Derraz 074e3371f2 feat: source mode text in pack readme 2026-04-01 14:52:25 +02:00
Abdessamad Derraz 85cc23398a feat: source-aware pack verification 2026-04-01 14:52:02 +02:00
Abdessamad Derraz 47a68c1a11 feat: add --source and --all-variants flags 2026-04-01 14:50:33 +02:00
Abdessamad Derraz 5f579d1851 feat: add source param to manifest and split packs 2026-04-01 14:44:39 +02:00
Abdessamad Derraz 423a1b201e feat: add source param to generate_pack 2026-04-01 14:39:04 +02:00
Abdessamad Derraz 9c6b3dfe96 feat: add include_all to _collect_emulator_extras 2026-04-01 14:33:54 +02:00
Abdessamad Derraz 0a272dc4e9 chore: lint and format entire codebase
Run ruff check --fix: remove unused imports (F401), fix f-strings
without placeholders (F541), remove unused variables (F841), fix
duplicate dict key (F601).

Run isort --profile black: normalize import ordering across all files.

Run ruff format: apply consistent formatting (black-compatible) to
all 58 Python files.

3 intentional E402 remain (imports after require_yaml() must execute
after yaml is available).
2026-04-01 13:17:55 +02:00
Abdessamad Derraz e5859eb761 refactor: dry pack integrity into cli and update docs
Move verification logic to generate_pack.py --verify-packs (single
source of truth). test_pack_integrity.py is now a thin wrapper that
calls the CLI. Pipeline step 6/8 uses the same CLI entry point.

Renumber all pipeline steps 1-8 (was skipping from 5 to 8/9).

Update generate_site.py with pack integrity test documentation.
2026-04-01 12:31:10 +02:00
Abdessamad Derraz 7beb651049 fix: correct core extras placement for retrodeck and romm packs
RetroDECK: core extras with subdirectory paths (e.g. vice/C64/,
fbneo/, dc/) were placed outside bios/ because the prefix was only
inferred for bare filenames. Add _detect_extras_prefix() to infer
the dominant BIOS prefix from YAML destinations.

RomM: core extras landed flat at bios/{file} instead of the required
bios/{platform_slug}/{file}. Add _detect_slug_structure() to detect
per-system slug layouts and _map_emulator_to_slug() to route each
extra to the correct slug subfolder.

Also skip manifest writes when only the generated timestamp changed,
preventing unnecessary diffs in install/*.json.
2026-04-01 11:08:01 +02:00
Abdessamad Derraz 6b5c3d8bf2 fix: pack conformance matches builder logic for perfect stats 2026-03-31 12:25:07 +02:00
Abdessamad Derraz b56f8dd05f feat: add archive_prefix for core-specific BIOS subdirectories
Closes #43

FBNeo and Kronos expect BIOS archives in core-specific subdirectories
(system/fbneo/, system/kronos/). RetroArch firmware check uses .info
paths which include these prefixes, so files at root show as Missing.

Add archive_prefix field to emulator profiles. The pack code now places
archive copies in the prefixed subdirectory while keeping root copies
for cores that expect them there (e.g. Geolith for neogeo.zip).
2026-03-31 09:17:54 +02:00
Abdessamad Derraz 17777f315b feat: agnostic bios mode for filename-agnostic emulators
bios_mode: agnostic (profile) and agnostic: true (file) for
emulators that accept any valid BIOS without specific filename.
find_undeclared_files skips agnostic entries, pack extras scan
includes all matching DB files by path prefix + size criteria,
resolve_local_file has agnostic fallback with rename README.
applied to pcsx2, lrps2 (bios_mode), melonds dsi_nand (file).
2026-03-30 14:18:54 +02:00