chore: stop committing client.js.map, which is where the conflicts were (#533) (#539)

@liuwenji007 proposed a bot that rebuilds client/ on PR branches, because
every front-end PR conflicts there after another one lands. The problem is
real — they were hitting it on three stacked PRs at once — but the diagnosis
narrows further than the proposal assumed.

Measured on the two committed artifacts:

  client/client.js       11,201 lines, unminified, real identifiers
  client/client.js.map        0 newlines — one 789KB line

Line-based merges handle the first and cannot handle the second. That
matches what the queue actually did: #511 rebased with zero conflicts, and
#518's only conflict is the map. The bundle is not the problem; the map is,
and it always will be, because a single-line file has no merge granularity
at all.

So: no sourcemap for the client bundle. The reasoning is about this
repository, not the browser — the map was bought for debugging, and the
bundle it maps is already readable, so a stack trace against it names the
real functions either way. Not worth a permanent tax on everyone who
touches the client.

It also rode along in the published package, where nothing consumed it:
1.0 MB → 809 kB packed, 3.9 MB → 3.1 MB unpacked.

What stays: the bundle is still committed (the market must install where
build scripts are blocked), CI still enforces that it matches the source,
and the pipeline still preserves line counts — that property serves
determinism as well as the map that is now gone.

The bot idea is declined separately on the issue; the short version is that
pushing to fork branches needs `pull_request_target`, which runs privileged
in the base repo's context against untrusted code.
This commit is contained in:
fkysly
2026-09-07 21:48:40 +08:00
committed by GitHub
parent 19a5d125ff
commit 8830b8bcac
4 changed files with 20 additions and 6 deletions
+3
View File
@@ -6,3 +6,6 @@ research/
npm-cache/
docs/
data/readmes-snapshot.json
# Generated when a local build enables sourcemaps; never committed (#533).
client/*.map
-2
View File
@@ -11198,5 +11198,3 @@ window.__ModuleLoader__.load({ id: "dshmarket", factory: (require) => {
return module.exports;
}
});
//# sourceMappingURL=client.js.map
File diff suppressed because one or more lines are too long
+17 -3
View File
@@ -44,9 +44,23 @@ export default defineConfig({
// Host types ship from lib/types (tsc); dts here would wrap the
// banner/footer into .d.cts and break parsing.
dts: false,
// Plugin code is fetched outside the host's module graph, so its own bundle
// carries the TS/TSX mapping consumed by browser profiling tools.
sourcemap: true,
// No sourcemap, and the reason is the repository rather than the browser.
//
// `client.js` is committed (the market must install where build scripts are
// blocked) and CI enforces that it matches the source. That is fine for the
// bundle itself: 11k unminified lines with real identifiers, which git
// merges line by line like any other file — measured across a run of
// front-end PRs, it did not conflict once.
//
// The map is one 789KB line. Every change to it is a whole-file conflict,
// for every contributor, every time another front-end PR lands first
// (#533 by @liuwenji007, who was hitting it on three stacked PRs). It also
// rode along in the published package, where nothing consumed it.
//
// The debugging it bought was small, because the bundle it maps is already
// readable — a stack trace against it names the real functions. Not worth a
// permanent tax on everyone who touches the client.
sourcemap: false,
clean: false,
external: [...CLIENT_EXTERNALS],
// tsdown auto-externalizes package dependencies; anything NOT in the loader