From 5cf5e511d658fb797c166526a0510469d9a8db7f Mon Sep 17 00:00:00 2001 From: kogai Date: Sun, 13 Sep 2026 07:48:39 +0000 Subject: [PATCH 1/2] Move to lts-23.25 (GHC 9.8.4) and stop pinning dependency versions MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The snapshot was lts-16.27, GHC 8.8.3, from 2020. Every dependency also carried an exact `== x.y.z` pin, which fights the snapshot: the versions have to be restated by hand on every bump, and any disagreement with the snapshot has to be papered over. Drop them and let the snapshot decide. base keeps its range. Checked that every non-boot dependency this package uses is in lts-23.25: mustache 2.4.3.1, yaml 0.11.11.2, vector 0.13.2.0, xml-conduit 1.9.1.4, http-client 0.7.19, http-client-tls 0.3.6.4, network-uri 2.6.4.2, optparse-applicative 0.18.1.0, HUnit 1.6.2.0. text, parsec, containers, transformers, bytestring and filepath ship with GHC. That makes two other things in stack.yaml unnecessary: - extra-deps pinned HUnit-1.6.1.0, which the snapshot now supplies, and a git checkout of typeable/xsd-parser that nothing depends on — it is absent from every build-depends list, so stack was resolving a 4.8 MB tree for a package that is never built. This repository has its own src/Xsd. - allow-newer: true, which disables version-bound checking globally. Pinned versions against a five-year-old snapshot probably needed it; with the snapshot in charge, hiding bound violations is the opposite of what we want. CI moves to GHC 9.8.4 to match, with stack "latest" — the snapshot is what pins the build, so pinning the tool as well only adds a number to maintain. stack.yaml.lock is written by hand rather than regenerated, since stack cannot run here (haskell.org is blocked by egress policy). The method was checked first by recomputing the existing lock's snapshot entry from lts-16.27 and getting byte-identical values (size 533252, sha256 c2aaae52…) before computing the new one. onix.cabal is hand-updated to match, hash refreshed the same way as before. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01P8rZakwAiz1jpViUX34x1Z --- .github/workflows/test.yml | 4 ++-- onix.cabal | 40 +++++++++++++++++++------------------- package.yaml | 38 ++++++++++++++++++------------------ stack.yaml | 7 +------ stack.yaml.lock | 28 +++++--------------------- 5 files changed, 47 insertions(+), 70 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index b8f4f2e..3951049 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -9,9 +9,9 @@ jobs: - uses: haskell-actions/setup@v2 id: haskell-setup with: - ghc-version: "8.8.3" + ghc-version: "9.8.4" enable-stack: true - stack-version: "2.5.1" + stack-version: "latest" - name: Restore caches uses: actions/cache@v4 with: diff --git a/onix.cabal b/onix.cabal index 373a58a..f3c8ce6 100644 --- a/onix.cabal +++ b/onix.cabal @@ -4,7 +4,7 @@ cabal-version: 1.12 -- -- see: https://github.com/sol/hpack -- --- hash: ccd13791926f8c74575d5f17648a17adbbe0740ce44707823a93b20ae5f7605c +-- hash: 07b4003dd4819b94016dc0a6629b5b634c96677c275eb19e5e97c2a6ac30ffd5 name: onix version: 0.1.0.0 @@ -42,19 +42,19 @@ library ghc-options: -Wall -fwarn-incomplete-patterns -fwarn-incomplete-uni-patterns build-depends: base >=4.7 && <5 - , bytestring ==0.10.10.1 - , containers ==0.6.2.1 - , filepath ==1.4.2.1 - , http-client ==0.6.4.1 - , http-client-tls ==0.3.5.3 - , mustache ==2.3.1 - , network-uri ==2.6.3.0 - , parsec ==3.1.14.0 - , text ==1.2.4.0 - , transformers ==0.5.6.2 - , vector ==0.12.1.2 - , xml-conduit ==1.9.0.0 - , yaml ==0.11.5.0 + , bytestring + , containers + , filepath + , http-client + , http-client-tls + , mustache + , network-uri + , parsec + , text + , transformers + , vector + , xml-conduit + , yaml default-language: Haskell2010 executable onix-exe @@ -67,7 +67,7 @@ executable onix-exe build-depends: base >=4.7 && <5 , onix - , optparse-applicative ==0.16.1.0 + , optparse-applicative default-language: Haskell2010 test-suite onix-test @@ -84,11 +84,11 @@ test-suite onix-test test ghc-options: -threaded -rtsopts -with-rtsopts=-N build-depends: - HUnit ==1.6.1.0 + HUnit , base >=4.7 && <5 - , containers ==0.6.2.1 + , containers , onix - , text ==1.2.4.0 - , vector ==0.12.1.2 - , xml-conduit ==1.9.0.0 + , text + , vector + , xml-conduit default-language: Haskell2010 diff --git a/package.yaml b/package.yaml index 50e6ae6..070f802 100644 --- a/package.yaml +++ b/package.yaml @@ -29,19 +29,19 @@ library: - -fwarn-incomplete-patterns - -fwarn-incomplete-uni-patterns dependencies: - - mustache == 2.3.1 - - text == 1.2.4.0 - - yaml == 0.11.5.0 - - vector == 0.12.1.2 - - xml-conduit == 1.9.0.0 - - parsec == 3.1.14.0 - - containers == 0.6.2.1 - - transformers == 0.5.6.2 - - bytestring == 0.10.10.1 - - filepath == 1.4.2.1 - - http-client-tls == 0.3.5.3 - - http-client == 0.6.4.1 - - network-uri == 2.6.3.0 + - mustache + - text + - yaml + - vector + - xml-conduit + - parsec + - containers + - transformers + - bytestring + - filepath + - http-client-tls + - http-client + - network-uri executables: onix-exe: @@ -56,7 +56,7 @@ executables: -fwarn-incomplete-uni-patterns dependencies: - onix - - optparse-applicative == 0.16.1.0 + - optparse-applicative tests: onix-test: @@ -68,8 +68,8 @@ tests: - -with-rtsopts=-N dependencies: - onix - - HUnit == 1.6.1.0 - - vector == 0.12.1.2 - - xml-conduit == 1.9.0.0 - - text == 1.2.4.0 - - containers == 0.6.2.1 + - HUnit + - vector + - xml-conduit + - text + - containers diff --git a/stack.yaml b/stack.yaml index daf1b09..0222475 100644 --- a/stack.yaml +++ b/stack.yaml @@ -18,7 +18,7 @@ # resolver: ./custom-snapshot.yaml # resolver: https://example.com/snapshots/2018-01-01.yaml resolver: - url: https://raw.githubusercontent.com/commercialhaskell/stackage-snapshots/master/lts/16/27.yaml + url: https://raw.githubusercontent.com/commercialhaskell/stackage-snapshots/master/lts/23/25.yaml # User packages to be built. # Various formats can be used as shown in the example below. @@ -29,7 +29,6 @@ resolver: # subdirs: # - auto-update # - wai -allow-newer: true packages: - . # Dependency packages to be pulled from upstream that are not in the resolver. @@ -41,10 +40,6 @@ build: library-profiling: true executable-profiling: true -extra-deps: - - HUnit-1.6.1.0 - - git: https://github.com/typeable/xsd-parser.git - commit: e08a37cf08674a492407b9b7f4a61e8faedb1590 # - acme-missiles-0.3 # - git: https://github.com/commercialhaskell/stack.git # commit: e7b331f14bcffb8367cd58fbfc8b40ec7642100a diff --git a/stack.yaml.lock b/stack.yaml.lock index 952b0ee..760127d 100644 --- a/stack.yaml.lock +++ b/stack.yaml.lock @@ -3,29 +3,11 @@ # For more information, please see the documentation at: # https://docs.haskellstack.org/en/stable/lock_files -packages: -- completed: - hackage: HUnit-1.6.1.0@sha256:62af6d70183d93944b98a8d9cb2ba4484b91303f74ebbb94425f7389d418c344,1572 - pantry-tree: - size: 878 - sha256: c42729ab00656f53d6a1114cf498574c62a8c595fa3d877639b5179a70dc6c8d - original: - hackage: HUnit-1.6.1.0 -- completed: - name: xsd-parser - version: 0.1.0.0 - git: https://github.com/typeable/xsd-parser.git - pantry-tree: - size: 4810413 - sha256: 4667e0d16862c182eb86d1d78a9cc390cd6d3f0012fa48957db477efa80f3281 - commit: e08a37cf08674a492407b9b7f4a61e8faedb1590 - original: - git: https://github.com/typeable/xsd-parser.git - commit: e08a37cf08674a492407b9b7f4a61e8faedb1590 +packages: [] snapshots: - completed: - size: 533252 - url: https://raw.githubusercontent.com/commercialhaskell/stackage-snapshots/master/lts/16/27.yaml - sha256: c2aaae52beeacf6a5727c1010f50e89d03869abfab6d2c2658ade9da8ed50c73 + size: 684278 + url: https://raw.githubusercontent.com/commercialhaskell/stackage-snapshots/master/lts/23/25.yaml + sha256: a3501d1b61a539371d85305fe73e1134fc08e7c97498a42952455f011fd97ecf original: - url: https://raw.githubusercontent.com/commercialhaskell/stackage-snapshots/master/lts/16/27.yaml + url: https://raw.githubusercontent.com/commercialhaskell/stackage-snapshots/master/lts/23/25.yaml From 310ef7eb3a2f4662058dc7c39c6cd83969f84143 Mon Sep 17 00:00:00 2001 From: kogai Date: Mon, 14 Sep 2026 02:28:09 +0000 Subject: [PATCH 2/2] Pin stack, and scope the cache to the toolchain MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Review's point: this PR pins the package set and then leaves the tool that resolves it floating. stack "latest" also decides which hpack runs, and stack regenerates onix.cabal on every build, so a stack release could silently rewrite a committed file with nothing checking for a dirty tree. Pin 3.11.1 (which bundles hpack 0.39.6). The cache key had the same shape of problem from the other side: it hashed package.yaml, onix.cabal and stack.yaml.lock but not GHC or stack, and fell back on a bare Linux- prefix — so a GHC 8.8.3 store could be restored into a 9.8.4 build. Put the toolchain in the key and in restore-keys. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01P8rZakwAiz1jpViUX34x1Z --- .github/workflows/test.yml | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 3951049..30d68b0 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -11,7 +11,7 @@ jobs: with: ghc-version: "9.8.4" enable-stack: true - stack-version: "latest" + stack-version: "3.11.1" - name: Restore caches uses: actions/cache@v4 with: @@ -19,9 +19,11 @@ jobs: ${{steps.haskell-setup.outputs.stack-path}} ~/.stack ./.stack-work/ - key: ${{ runner.os }}-${{ hashFiles('**/package.yaml') }}-${{ hashFiles('**/onix.cabal') }}-${{ hashFiles('**/stack.yaml.lock') }} + key: ${{ runner.os }}-ghc9.8.4-stack3.11.1-${{ hashFiles('**/package.yaml') }}-${{ hashFiles('**/onix.cabal') }}-${{ hashFiles('**/stack.yaml.lock') }} + # Scoped to the toolchain: a bare ${{ runner.os }}- prefix would happily + # restore a GHC 8.8.3 store into a 9.8.4 build. restore-keys: | - ${{ runner.os }}- + ${{ runner.os }}-ghc9.8.4-stack3.11.1- - run: make test e2e: name: Test e2e