4.0 KiB
phase, title, status, priority, effort, dependencies
| phase | title | status | priority | effort | dependencies | |
|---|---|---|---|---|---|---|
| 2 | Phase 2: Pin the source | done | P1 | 2h |
|
Phase 2: Pin the source
Overview
Point the build machinery at the new file: pinned by commit and checksum, fetched by
make fetch-dict and by the Docker dictionary stage, with the existing agreement test
still guarding both.
Requirements
- Functional:
make fetch-dictdownloads the pinned JSONL and verifies its SHA-256;make dictbuildsdata/noitu.dbfrom it. - Functional: the Docker
dictstage does the same, and its fixture escape hatch (FIXTURE_DICT=1) keeps working untouched. - Functional: the fetched source file is gitignored — we distribute the derived database, never a copy of their file.
- Non-functional:
DICT_URL/DICT_SHA256keep their names soweb/tests/dictionary-source.test.jscontinues to guard Makefile/Dockerfile agreement with no change to the test.
Architecture
The pin is a commit-addressed raw URL, which is immutable — unlike master, where the
URL and the checksum could silently diverge:
DICT_URL := https://raw.githubusercontent.com/undertheseanlp/dictionary/2c078cfc373b06e2980d324ce1d7bd13740c3319/dictionary/words.txt
DICT_SHA256 := 4c3e0e6117e4bdfa97731e135c3d4a05881889909267394a8de8d88ef79f13f0
DICT_SRC := data/undertheseanlp-words.jsonl
fetch-dict and verify-dict keep their current shape — curl then sha256sum -c —
because that is already the right shape; only the size in the help text changes.
Related Code Files
- Modify:
Makefile—DICT_URL,DICT_SHA256,DICT_SRC, thedicttarget's flags (--mergedin place of--in), and thehelptext's "~179 MB" - Modify:
Dockerfile—ARG DICT_URL,ARG DICT_SHA256, thecurl/sha256sumlines, thebuild-dictionaryinvocation, and theFIXTURE_DICTcomment's 179 MB reference - Modify:
.gitignore— ignoredata/undertheseanlp-words.jsonl(data/*.dbalready covers the derived and old source databases) - Verify unchanged:
web/tests/dictionary-source.test.js,.github/workflows/ci.yml
Implementation Steps
- Update the three Makefile variables and the
dicttarget to pass--merged $(DICT_SRC).--sourcesis left at itswiktionarydefault so the Makefile and Dockerfile carry one fewer thing to keep in agreement. - Reword
help,fetch-dictand the$(DICT_SRC)guard: the download is ~4.8 MB now, and saying "179 MB" would be the kind of stale comment that outlives three refactors. - Mirror all of it in the Dockerfile stage. Keep
FIXTURE_DICT=1on--words— the image smoke test must not start needing a network. - Add the source file to
.gitignoreand confirmgit statusis clean after a fetch. - Run
make fetch-dict && make verify-dict && make dictend to end from a cleandata/. - Run
npm testinweb/—dictionary-source.test.jsshould pass untouched. If it needs editing, the variable names were changed unnecessarily; put them back. - Build the image with and without
FIXTURE_DICT=1and confirm both produce a database.
Success Criteria
make fetch-dictpulls 4,813,111 bytes and the checksum verifies.make dictproducesdata/noitu.dbwith the Phase 1 word count.web/tests/dictionary-source.test.jspasses with no edits to it.docker buildsucceeds both withFIXTURE_DICT=1and without.git statusis clean after a fetch — no source file staged, ever.- No file in the repository still claims a 179 MB dictionary download.
Risk Assessment
raw.githubusercontent.com is not an archive. An 8-year-dormant repository could be
deleted or renamed, and then make fetch-dict fails for everyone. Signal: a 404 on fetch.
Response: the checksum makes any mirror verifiable, so host a copy as a release asset on
this repository and re-pin to it. Worth doing pre-emptively if the build ever gates CI.
The Docker stage and the Makefile drift. Signal: the agreement test fails. Response: that is the test doing its job — fix the file that is behind, and do not weaken the test to match.