Commit Graph
189 Commits
Author SHA1 Message Date
Abdessamad Derraz 3d9df87dd0 fix: follow linked dirs and ask for a platform 2026-09-03 17:51:08 +02:00
Abdessamad Derraz 232ef1a6b8 fix: let the constrained declaration win in manifests too
A destination can be declared by more than one system, bare in one and
hash-constrained in another. generate_pack resolves that with
_preferred_entries so the constrained sibling claims the destination;
generate_manifest never did, and named whatever answered to the name.

RetroDECK's bios/d2fdc.zip is the case: declared with an md5 in the
arcade system and bare under apple-ii. The pack carried the right
archive, 262 bytes reached through the MAME clone map, while the
manifest sent install.py to a 256-byte Apple II ROM. Downloading the
ZIP and running the installer gave different files.

A test now hashes every manifest entry a platform pins and compares it
against what the platform declares: 3295 entries, on the platforms whose
frontend reads the bytes. It accepts any of several declarations for one
destination, the member-composite MD5 Recalbox pins for arcade archives,
and Batocera's 29-character prefixes. Reinstating the old manifest entry
fails it.
2026-08-23 12:14:56 +02:00
Abdessamad Derraz 3a266be7a5 fix: keep the contributors when the request fails
The contributors block is the only part of the README that comes from
the network, and a refused request returned an empty list, which deleted
the section. That happened during a pipeline run and the result was
committed; the freshness check then regenerated the section and failed
on the difference.

An unavailable list now republishes the one already there and says so.
Losing it is a worse answer than a stale one, and it makes an offline
regeneration additive rather than destructive. Reverting the change and
simulating the same outage empties the section again.
2026-08-23 09:59:26 +02:00
Abdessamad Derraz 8b404e500f fix: keep a packed file's executable bit
Pinning every member's metadata made packs reproducible and took the
executable bit with it. The RetroDECK pack ships the two Voxatron engine
binaries, and extracted at 644 they cannot be run.

Git records the bit, so reading it from the source file keeps a pack the
same from any clone. Nothing else about the source's mode reaches the
archive: 2569 members ship at 644 and 942 at 755, which is what the
builder produced before the pinning.

Nothing caught this. The comparison that proved the pinning inert
checked member names, CRCs and sizes, and mode is none of those. A test
now builds a runnable payload and asserts it survives extraction.

RetroDECK rebuilds to the same bytes twice and passes its integrity
check, 2008/2008 baseline and 1551/1551 cores.
2026-08-23 07:58:23 +02:00
Abdessamad Derraz 593b277bc4 refactor: one place decides which profiles answer
The verifier and the builder each resolved the profiles a run names, in
thirty-five lines that differed only in how they failed: one exits, the
other returns empty-handed. An alias is the same binary under another
name and a launcher only starts an emulator, so neither has requirements
of its own, and both refusals have to say the same thing.

common raises now and each caller chooses its own ending. Six tests hold
the refusals, one of them reading both sources so a copy cannot grow
back. The manifest's core-complement phase comes out of generate_manifest
in the same pass, 60 to 34.

Verified inert: manifests identical entry for entry, and the Handy pack
rebuilds to the same bytes.
2026-08-23 07:18:41 +02:00
Abdessamad Derraz 77b06bcb1b test: cover the emulator pack's own build path
generate_emulator_pack is a distinct build path from the platform packs,
and nothing asserted that it produced the same bytes twice. It does, but
only because every member write was routed through one writer: restoring
the mtime-copying write on that path alone fails the new test and no
other.
2026-08-23 06:53:15 +02:00
Abdessamad Derraz bf3196ce06 refactor: name the gap filter's two kinds of skip
find_undeclared_files decided per entry whether a core requirement can
be a gap, through a chain that mixed two skips whose difference is easy
to lose. Some record the requirement as settled so no other profile
reconsiders it; the rest leave it open, because the same file can be
libretro-only in one profile and standalone-only in another and the key
carries no emulator.

The chain returns a named verdict now, complexity 60 to 45. Twelve tests
cover the verdicts and two more cover the distinction end to end: a
standalone-only entry seen first must not answer for the profile that
needs the file. Collapsing the two skips into one passes every other
test in the suite and fails that pair.
2026-08-12 16:44:30 +02:00
Abdessamad Derraz c313b32347 chore: neutral report path and plain punctuation
The markdown report wrote to a directory named after the tooling that
happened to produce it. It takes --report-dir now, defaulting to
reports/, so nothing in the tree names anything but the project.

Em-dashes replaced throughout the sources and tests, rephrased rather
than swapped for a comma where the dash carried an apposition.
2026-08-12 16:16:52 +02:00
Abdessamad Derraz 6aa5685fc7 refactor: split the extras collector into its passes
_collect_emulator_extras ran three passes in one body: the undeclared
files a platform's cores need, a second copy of an archive under the
subdirectory some cores read, and the scan a filename-agnostic core
allows. The last two are named now, complexity 98 to 54.

The archive-prefix pass had no test, and extracting it surfaced why that
mattered: it read an index from the enclosing scope, so on its own it
would have raised. Three tests cover it, including the case it exists to
prevent - claiming a prefixed path for an archive the collection does
not hold.
2026-08-12 15:46:02 +02:00
Abdessamad Derraz 53fc5b7005 refactor: name the resolver's weakest steps
resolve_local_file is an ordered chain where the order is the policy:
content first, then a declared path, then a filename. The last steps -
the walk through the cached data directories and the shape-only match a
filename-agnostic core allows - were inline, and the predicate judging a
candidate found by name was a closure with no test of its own.

All three are named now, and the predicate is the interesting one: it
decides whether a file the walk found by filename actually satisfies
what the entry declares. Sixteen tests cover it, including the truncated
MD5 prefixes Batocera publishes and the case where one hash matches
while another is contradicted. Accepting a name match without checking
content fails nine of them.

Complexity 164 to 143. Verified inert against the previous revision on
frozen inputs.
2026-08-12 15:30:13 +02:00
Abdessamad Derraz a2bd197b9b fix: pin every pack member to a fixed date
A pack was still not a function of its inputs. ZipFile.write copies the
source file's mtime into the member: the wall clock for an archive this
build rebuilt in tmp/, the checkout time for a file from the collection.
Two consecutive builds of the Recalbox pack differed on 348 members
whose content matched byte for byte, and a pack built from a fresh clone
could never match one built from another.

Every member now goes through one writer that stamps the epoch the
archive rebuilder already uses, streaming the content so a firmware
image of several hundred megabytes is not read whole.

The pack was already covered by a two-builds-are-identical test, which
passed: its fixture held no romset, so it never reached the rebuild
path. The fixture has one now, and reverting the writer fails both that
test and the new one.

Verified on the real collection: Recalbox and RetroArch rebuild to the
same bytes twice, contents unchanged from the previous revision (1319
and 4517 members, zero CRC differences), and both still pass their
native integrity check.
2026-08-12 15:14:48 +02:00
Abdessamad Derraz f8fe1d1464 test: cover the site writer and its sweep
The generated tree is swept rather than deleted, which puts a delete on
the build's critical path with only an end-to-end comparison behind it.
Fourteen tests hold the three behaviours that matter: front matter is
recognised and stripped for the body comparison but not for the
decoration's own, a rebuild on unchanged inputs writes nothing and keeps
its front matter, and the sweep removes a page only when nothing
produced it. Reverting any of the three fails at least two of them.
2026-08-12 14:24:05 +02:00
Abdessamad Derraz 306637d90e chore: declare scripts as a package
The modules are run directly, run with -m, and imported by the tests and
the type checker. Only the first form puts this directory on the path, so
the package marker carries the bootstrap the other two need; without it
the first sibling import fails. Three tests hold the three forms open.
2026-08-12 12:47:01 +02:00
Abdessamad Derraz b5fd643ccf refactor: give common.py's parts their own modules
common.py had grown to 1833 lines by accumulation. Six coherent pieces
move out - untrusted parsing, digests, archives, generated artefacts,
release assets, dump catalogues - and common.py re-exports them, so the
sixty existing import sites keep working and migrating them stays
optional.

The site build is now reproducible, which is what made the move
checkable. It deleted its generated directories first, so every page was
new and write_if_changed had no earlier version to compare against: a
deploy republished six hundred pages for the clock alone. Directories
are swept instead, a page is removed only once nothing produces it, and
the body pass compares against the body of the file on disk rather than
against the decorated page. Two consecutive builds on the same inputs
now produce identical bytes; before, 1034 files differed.
2026-08-12 11:49:54 +02:00
Abdessamad Derraz 5e168b86c8 refactor: ask the mode module instead of retyping it
Four sites still compared the verification mode to a literal after the
module owning that policy existed. One of them mattered: an unrecognised
mode fell through to MD5 verification while compute_severity was scoring
it as existence, so a typo in a platform YAML produced a report whose
checks and severities described different platforms.

The mode is normalized once per run and the consumers ask for what they
need. A test reads the sources and fails on a literal comparison, so the
next consumer cannot quietly grow a fifth copy.
2026-08-12 07:36:29 +02:00
Abdessamad Derraz b11c8b0638 fix: keep the agnostic scan inside its own tree
A filename-agnostic core accepts any name for its BIOS, so the builder
scans the directory holding the candidates. It picked that directory
from a first-hit lookup by name, the one piece of evidence that lands
in another emulator's tree: five files answer to GameIndex.yaml and one
belongs to an Android package, rom1.bin is a PS2 ROM and a Roland
SC-55 ROM. One wrong match became every file beside it, flattened into
the BIOS root of platforms that do not run that emulator: 45 files in
the Recalbox pack, 170 in the RetroArch one.

Four things decide it now. A destination and the repo layout meet on a
tail, so the path index is tried from the longest tail down and never
to the bare filename; that alone corrects seven files, among them the
Japanese GameCube slot, which held the US dump. A seed has to declare
the shape it is looking for, since no shape means the whole directory.
An ambiguous name needs the profile's other files to agree before the
scan walks anywhere. What the scan emits carries the SHA-1 it selected,
so packing never resolves it by name again.
2026-08-12 07:23:23 +02:00
Abdessamad Derraz b33d045175 fix: group region candidates once for both sides
The builder and the coverage report each grouped their own candidates
before asking which regional alternatives to withdraw. The builder
grouped the platform files and the core extras; the report grouped the
platform files alone, and keyed them on an unsanitized destination.

So a region run withdrew 73 files from a recalbox pack while the report
withdrew 14, and described the other 59 as covered by a pack that would
not carry them.

platform_region_groups builds the grouping once and both sides read it.
The extras it returns are keyed by emulator, name and path: Dolphin
declares three IPL.bin that differ by path alone, and a name-keyed map
withdraws the wrong one. Manifests are byte-identical before and after.
2026-08-12 06:43:47 +02:00
Abdessamad Derraz 34619c778f fix: publish target aliases and refuse an unknown one
The pack builder accepts the aliases declared in the target overrides,
so --target switch works there, but the installer's target manifests
carried only canonical names. The documented word was the one that
failed, and the installer then carried on with every file: 1911 files
and 4.1 GB where the user had asked for the 863 that target needs.

Aliases are emitted beside their canonical target, and an unknown
target now stops the run and lists what is available. A filter is
applied or refused, never ignored.
2026-08-12 06:13:21 +02:00
Abdessamad Derraz f998f4d77a fix: judge core extras by content where the builder does
The gap analysis answered from the name index, so a core extra whose
local copy contradicts its declared hash counted as held. Under a
digest mode the builder drops exactly that file, so the coverage report
described a pack that would not contain it: seven files across
Batocera, Recalbox and RetroBat.

An entry that states what its content should be is now resolved by
content; the name still answers for entries that declare nothing to
check against, and existence mode is unchanged because there the
frontend never opens the file and the pack does carry it.
2026-08-12 05:38:16 +02:00
Abdessamad Derraz b28f8d12a3 feat: report unsourceable entries apart from gaps
The per-emulator report counted an entry nobody can supply -- a
per-user key, a slot the user fills, a dump that was never made -- as
plainly missing. fpse-ng read 14 missing when twelve were documented as
unobtainable, which invites the wrong repair: dropping the flag,
deleting the entry, or chasing a vendor's whole install tree.

They are listed with the reason the profile records rather than hidden,
and the summary counts them apart. Platform reports are untouched.
2026-08-12 05:20:25 +02:00
Abdessamad Derraz f097184b00 fix: stop counting a contradicted hash as covered
The per-emulator report captured the status resolve_local_file returns
and then ignored it: any non-empty path became OK. An entry whose only
candidate contradicts its declared hash therefore read as covered, so a
same-named file from another system stood in for one the collection
does not hold. 36 entries across 14 profiles were affected, among them
config.ini, ROM and rom2.bin, names that collide across systems.

Emulator validation still runs first, since it names the field that
disagrees; the resolution status is consulted only when validation had
nothing to say.
2026-08-12 04:21:54 +02:00
Abdessamad Derraz 45ced32598 docs: drop tooling references from test docstrings
Three docstrings pointed at a contributor-guide file that is not part
of the repository. The rules they describe are stated directly now.
2026-08-12 03:44:25 +02:00
Abdessamad Derraz 7c043475cd feat: follow mame clones in the gap analysis 2026-08-12 03:15:05 +02:00
Abdessamad Derraz b86a34933c feat: parse gamel machines and computed sizes 2026-08-12 03:15:05 +02:00
Abdessamad Derraz 6719aa415d feat: anchor prose citations beside source refs 2026-08-12 03:11:47 +02:00
Abdessamad Derraz b120528dd7 test: cover the native format exporters
export_native turns the profile data back into each platform's own
file, for a maintainer there to pick up and use, and none of the ten
exporters had a test. Coverage goes from 0 to 83%.

Writing them found the EmuDeck exporter rejecting its own output: its
export skips placeholder entries, its validate looked for them anyway
and reported the omission as a missing hash. Both sides apply the same
filter now.

The placeholder assertion initially passed for the wrong reason twice
over -- the fixture entry had no hash, so it was dropped as incomplete
rather than as a placeholder, and the assertion then read the name
while the exporters write the path. It is pinned on an unmistakable
destination now, and removing the guard fails two tests.
2026-08-12 00:46:04 +02:00
Abdessamad Derraz 00f10b0379 refactor: extract rename matching from the truth diff
_diff_system reached complexity 42, and its hash-based rename fallback
is the part that stands alone: a platform is free to call a file
whatever it likes, so a name matching nothing is not yet a gap, and
counting one file as both missing and extra invents a discrepancy.

That step is now its own function at complexity 31, with the tests it
never had: pairing on any of the three digests, case folding, non-string
values, and the case where two files simply have no hashes and so are
not evidence of anything. diff_truth output is unchanged.
2026-08-11 19:54:45 +02:00
Abdessamad Derraz 4b8d7baac5 feat: transcribe bios search orders into priority 2026-08-11 19:18:30 +02:00
Abdessamad Derraz d28efae88c fix: stop git normalising preserved bytes
SHA1 is the primary key of this collection and there was no
.gitattributes, so git guessed. Git for Windows sets core.autocrlf=true
by default: a clone there rewrites every file git considers text,
meaning the shaders, .ini, .txt and .dat assets under bios/ arrive with
CRLF and a different hash from the one published. Verification then
fails on files nobody touched.

bios/ and data/ are exempt from normalisation, generated artefacts are
pinned to LF so a Windows checkout does not show them modified, and the
rule order is asserted rather than assumed.
2026-08-11 18:52:10 +02:00
Abdessamad Derraz 4ecb65b8d9 fix: keep the mame clone map across runs
A clone group is only visible while both copies are on disk, and the
run then deletes the clone, so writing only what this run saw erased
every mapping an earlier run had recorded. One real run took the map
from 69 entries to 1, and the canonical zips silently stopped answering
to the names they stand in for.

The map is merged now, the 68 lost entries are restored, and the one
whose canonical file is no longer in the collection is dropped.
2026-08-11 18:41:04 +02:00
Abdessamad Derraz 58ca2689f1 test: pin the rules dedup must not get wrong
dedup.py is the only script here that deletes BIOS files and it had no
tests: the sole guard was remembering --dry-run. These cover the
protected directories where two identical copies are both load-bearing,
the canonical choice between a primary and a variant, MAME zip clones
against same-content files that must keep every name, and that a dry
run reports exactly the plan the real run executes.

Disabling the NODEDUP guard fails four of them.
2026-08-11 18:10:20 +02:00
Abdessamad Derraz 36a284b93b fix: name and announce every narrowed pack 2026-08-11 17:54:28 +02:00
Abdessamad Derraz 4bd277a7be feat: name every narrowing in the pack filename 2026-08-11 16:56:20 +02:00
Abdessamad Derraz e53f7dfafc test: cover the four 3DS unique-data verifiers
verify.py reaches these through a dynamic import and nothing exercised
them, so a signature check that accepted everything would have looked
exactly like one that worked.

Console dumps are personal data and cannot be committed, but the
verifiers only read structure and signatures: the fixtures are built
from the layouts in unique_data.cpp and otp.cpp, signing with a key the
test owns and passing the matching public key in through the keys file.
That covers the region-change detection in SecureInfo_A, the embedded
LFCS in movable.sed, and the OTP path down to the sect233r1 certificate
including the pre-v5 expiry endianness.

crypto_verify goes from 9 to 89 percent. Disabling the OTP hash check
and the movable.sed magic check each fails a test.
2026-08-11 16:31:35 +02:00
Abdessamad Derraz d37caecc27 test: cover slot naming and per-system extras 2026-08-11 16:06:20 +02:00
Abdessamad Derraz 627cc84a78 test: skip pack checks while a build holds dist
The pack integrity tests failed whenever another run was writing
dist/, reporting a corrupt archive when the only fact established was
that somebody else was building. Which test went red depended on how
far along that build was. They skip now, the way validate_schemas
already does.
2026-08-11 16:05:57 +02:00
Abdessamad Derraz e97c1fbbcc fix: keep unsourceable files from matching homonyms 2026-08-11 14:40:33 +02:00
Abdessamad Derraz 94512b5acf fix: drop manifest entries with no download source
install.py fetches a file from its repo_path or from a release asset.
Resolution can land on a file the database does not index, and the
entry then shipped with neither: a line in the download list that can
only ever fail. Those are recorded as omitted instead, which is what
the installer already knows how to report, and a test holds the
committed manifests to it.

validate_schemas read dist/ while a build was writing it and reported
a half-written pack as 'File is not a zip file'. It takes the shared
lock --verify-packs uses, and says so when a build holds it.
2026-08-11 14:40:33 +02:00
Abdessamad Derraz 85f3f7c393 fix: read the bios preference order the code applies 2026-08-11 14:34:49 +02:00
Abdessamad Derraz a372f2abf3 feat: keep one bios per slot on declared order 2026-08-11 13:34:15 +02:00
Abdessamad Derraz ecbe69760d refactor: check packs through a single path 2026-08-11 11:31:21 +02:00
Abdessamad Derraz d8a0d975d7 feat: judge a ref against every declared repository 2026-08-11 07:25:31 +02:00
Abdessamad Derraz 3bc9e5ec96 feat: attribute a shared path by its declared subject 2026-08-11 05:42:27 +02:00
Abdessamad Derraz d8e4325af2 fix: skip conformance on required-only packs
A required-only build is narrower than the platform declares by
design, like the source-restricted variants already handled, so the
full expectation must not be applied to it. --region is also refused
alongside --manifest-targets, which carries no region dimension.
2026-08-11 05:34:21 +02:00
Abdessamad Derraz cc24ff1bea fix: ignore the rendered timestamp when comparing
Decorated site pages carry the generation stamp twice: once as the
markdown footer and once as a rendered element. write_if_changed knew
only the first, so every page was rewritten on every run for the clock
alone.

The comparison is what makes the deploy-site freshness guard a real
staleness check rather than a guaranteed failure, and it had no tests.
2026-08-11 05:23:52 +02:00
Abdessamad Derraz 0d59979f2a fix: pin the digest order in cached entries
The cached hashes were rebuilt by iterating a set, so their order in
each database entry followed set hashing rather than a declared one. A
run with a warm cache rewrote all 7,850 entries with no content change.
The order is now the one compute_hashes returns, and a test holds a
warm-cache run byte-identical to a --force rehash.
2026-08-11 01:46:46 +02:00
Abdessamad Derraz 0b5c534af4 fix: settle a contributed path before reading it
validate_pr.py inspects paths chosen by whoever opened the pull
request, and it hashed the file before deciding whether it was a
symlink. A link to /dev/zero was read until the job timed out, and a
link out of the checkout was hashed and reported as though its target
had been contributed. The shape is now settled first, and a test that
used to hang the run covers it.

The gate had no tests at all, and neither did the 3DS crypto reached
by dynamic import from validation.py: RSA PKCS#1 v1.5, AES-128-CBC and
ECDSA over GF(2^233), all written by hand. Coverage goes from 0 to 95%
on the curve, 0 to 55% on the gate, 9 to 35% on the rest. The curve
tests check against the published SEC 2 parameters rather than against
the module: the generator satisfies the curve equation and the group
order takes it to infinity.
2026-08-11 01:39:29 +02:00
Abdessamad Derraz 367d4efaac feat: tag filtered packs by region and target
A region- or target-filtered build wrote to the same filename as the
full one. Both filters now appear in the pack and manifest names, and
verify.py accepts --region for emulator and system reports so the
coverage figures come from the same selection the builder used.
2026-08-11 00:56:14 +02:00
Abdessamad Derraz 87e19191b6 fix: pair each source repository with its own pin
A profile whose builds live in separate repositories keys source,
upstream and source_commit by build mode. The site flattened the URLs
but read a single scalar revision, so a libretro fork could be pinned
to the standalone commit, and binding the object form into SQLite
failed outright once ymir adopted it. URL and revision are now read as
pairs.

The site also published a sitemap nothing pointed at, so robots.txt is
generated alongside it.
2026-08-11 00:56:00 +02:00
Abdessamad Derraz 24e9b820ae feat: make packs reproducible byte for byte
Two builds of the same pack from the same inputs produced different
archives. Of 67 members, 65 were already identical: only README.txt
and manifest.json differed, both stamped with the wall clock by
writestr and the second carrying a generated timestamp. Generated
members now use the epoch the archive rebuilder already applies, and
the timestamp comes from the database snapshot the pack was built
from, so the same data yields the same bytes.

Install manifests skipped archived platforms, which is why RetroPie
had none; archived means upstream is no longer scraped, not that the
packs stopped shipping. A target-filtered manifest also had no record
of its filter beyond the filename, so it carries one the way a
region-filtered manifest already does.
2026-08-11 00:55:42 +02:00