#!/usr/bin/env bash
# The committed dist/ must be exactly what a fresh build of src/ produces —
# a stale dist would ship behavior the sources don't show. Also the two-stack
# tripwire: each process entry may name only its own kit stack.
set -euo pipefail
cd "$(dirname "$0")/.."
# a stale in-tree shadow cache can mask clean-clone divergence
rm -rf .shadow-cljs
npm run --silent build >/dev/null
if [ -n "$(git status --porcelain dist)" ]; then
echo "ABORT: dist/ is stale — commit the rebuilt output first:" >&2
git status --porcelain dist >&2
exit 1
fi
# macOS home-dir prefix, built from pieces: the published bytes of this
# script must never contain the pattern the idpat leak scan hunts for
LEAKPAT='/Use''rs/'
if grep -rF "$LEAKPAT" dist; then
echo "ABORT: local filesystem path embedded in dist/" >&2
exit 1
fi
# ---- the two-stack law (house rule 11) --------------------------------------
# dist/main.js (stack A) must never name the rooms-kit stack: two builds of
# libdatachannel in one process abort it (ThreadSafeCallback cancellation).
if grep -qE 'ardegazu-rooms-kit|@ipshipyard' dist/main.js; then
echo "ABORT: dist/main.js references the rooms-kit stack (two-stack law)" >&2
exit 1
fi
# dist/worker.js (stack B) must never name the peer-kit stack.
if grep -qE 'ardegazu-peer-kit|"node-datachannel"' dist/worker.js; then
echo "ABORT: dist/worker.js references the peer-kit stack (two-stack law)" >&2
exit 1
fi
# dist/rl/train.js (stack A + train-kit) must never name the rooms-kit stack
# either — the trainer is a peer-kit-side process, and this grep keeps it so
# when someone reaches for a "convenient" require.
if grep -qE 'ardegazu-rooms-kit|@ipshipyard' dist/rl/train.js; then
echo "ABORT: dist/rl/train.js references the rooms-kit stack (two-stack law)" >&2
exit 1
fi
echo "check-dist: OK (committed dist matches a fresh build, no local paths, two-stack clean)"