Conversation
The snapshot was lts-16.27, GHC 8.8.3, from 2020. Every dependency also carried an exact `== x.y.z` pin, which fights the snapshot: the versions have to be restated by hand on every bump, and any disagreement with the snapshot has to be papered over. Drop them and let the snapshot decide. base keeps its range. Checked that every non-boot dependency this package uses is in lts-23.25: mustache 2.4.3.1, yaml 0.11.11.2, vector 0.13.2.0, xml-conduit 1.9.1.4, http-client 0.7.19, http-client-tls 0.3.6.4, network-uri 2.6.4.2, optparse-applicative 0.18.1.0, HUnit 1.6.2.0. text, parsec, containers, transformers, bytestring and filepath ship with GHC. That makes two other things in stack.yaml unnecessary: - extra-deps pinned HUnit-1.6.1.0, which the snapshot now supplies, and a git checkout of typeable/xsd-parser that nothing depends on — it is absent from every build-depends list, so stack was resolving a 4.8 MB tree for a package that is never built. This repository has its own src/Xsd. - allow-newer: true, which disables version-bound checking globally. Pinned versions against a five-year-old snapshot probably needed it; with the snapshot in charge, hiding bound violations is the opposite of what we want. CI moves to GHC 9.8.4 to match, with stack "latest" — the snapshot is what pins the build, so pinning the tool as well only adds a number to maintain. stack.yaml.lock is written by hand rather than regenerated, since stack cannot run here (haskell.org is blocked by egress policy). The method was checked first by recomputing the existing lock's snapshot entry from lts-16.27 and getting byte-identical values (size 533252, sha256 c2aaae52…) before computing the new one. onix.cabal is hand-updated to match, hash refreshed the same way as before. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P8rZakwAiz1jpViUX34x1Z
総評移行そのものは妥当で、検証可能な主張はすべて独立に再現して一致しました(lock の size/sha256、hpack ハッシュ、lts-23.25 のパッケージ在庫、
|
Review's point: this PR pins the package set and then leaves the tool that resolves it floating. stack "latest" also decides which hpack runs, and stack regenerates onix.cabal on every build, so a stack release could silently rewrite a committed file with nothing checking for a dirty tree. Pin 3.11.1 (which bundles hpack 0.39.6). The cache key had the same shape of problem from the other side: it hashed package.yaml, onix.cabal and stack.yaml.lock but not GHC or stack, and fell back on a bare Linux- prefix — so a GHC 8.8.3 store could be restored into a 9.8.4 build. Put the toolchain in the key and in restore-keys. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P8rZakwAiz1jpViUX34x1Z
|
非常に密度の高いレビューをありがとうございます。推奨 2 件を反映し (310ef7e)、必須 2 件については 1 つを実測で潰し、もう 1 つは実行できない旨をお伝えします。 必須 1: xml-conduit の
|
Haskell 側のツールチェーンは 2020 年の lts-16.27 / GHC 8.8.3 で止まっていました。base は #60(未使用依存の削除)。
固定バージョンをやめます
全依存に
== x.y.zの完全固定が付いていましたが、これはスナップショットと喧嘩します。更新のたびに手で書き直す必要があり、スナップショットと食い違えばそれを回避する仕掛けが要ります(実際allow-newer: trueが入っていました)。固定を外し、スナップショットに任せます。baseの範囲指定だけ残しています。lts-23.25 に必要なパッケージが揃っていることは確認済みです。
textparseccontainerstransformersbytestringfilepathは GHC 同梱です。ついでに落ちるもの
extra-depsが丸ごと不要になりました。HUnit-1.6.1.0— スナップショットが 1.6.2.0 を提供しますtypeable/xsd-parserの git 依存 — どこからも使われていません。 どのbuild-dependsにも現れず、このリポジトリは自前のsrc/Xsd/を持っています。つまり stack は、ビルドされることのないパッケージのために 4.8 MB のツリーを解決していましたallow-newer: trueも削除。 バージョン境界のチェックを全体で無効化する設定で、5 年前のスナップショットに完全固定を組み合わせていた事情なら分かりますが、スナップショットに任せる以上、境界違反を隠すのは逆効果です。stack.yaml.lock を手で書いている点
この環境では stack を実行できません(
haskell.orgが egress ポリシーでブロック)。そこで手法を先に検証しました。既存 lock の lts-16.27 のエントリを自分で再計算し、コミット済みの値と完全一致することを確認してから、新しい値を求めています。onix.cabalも同様に手で更新し、hpack のハッシュを再計算しています(#60 で検証済みの方法)。確認
onix.cabalのハッシュ自己整合性を確認🤖 Generated with Claude Code
https://claude.ai/code/session_01P8rZakwAiz1jpViUX34x1Z
Generated by Claude Code