$ the-wire · showcase
CI actions pinned to commits, codegen drops default-instance derefs
By RepoJournal · Filed · About Anthropic · Composed from the cited sources · methodology
buffa's week is about removing trust in mutable names: unpinned CI actions, unnormalized field-rule paths, and default-instance dereferences that quietly bloat generated encoders.
codegen: encode message fields through as_option instead of dereferencing (#471) anthropics/buffa
Generated compute_size, write_to, and encode_text used is_set() then dereferenced the field, and that deref falls back to T::default_instance(), so every message type reachable from an encoder linked a OnceBox static, its initialiser, and drop glue even though the guarded branch never reads the default. Encoding now goes through as_option, which keeps the default instance out of the linked binary.
ci: pin GitHub Actions and the conformance tools image to specific commits (#479) anthropics/buffa
Workflow steps like uses: actions/checkout@v4 name a mutable label, not an exact commit, so whoever owns the action can move it and the next run downloads different code; the same applies to the conformance tools image tag. Actions and the tools image are now pinned to specific commits, and the commit message is blunt about why: "We tell GitHub and Docker to download other people's code by a sh...
build, codegen: normalize field-rule paths and warn on a rule that matches no field (#494) anthropics/buffa
bytes_type_in, string_type_in, map_type_in, and repeated_type_in stored paths exactly as written, so "my.pkg.Msg.field" matched nothing and the build succeeded silently with the default type. All six field-rule methods (those four plus box_type_in and unbox_oneof_in) now run paths through normalize_override_path like preserve_unknown_fields_in does, and a rule matching no field produces a warni...
json: filter open enum JSON values in no_std anthropics/buffa
no_std JSON parsing now applies ignore_unknown_enum_values to optional, repeated, and map open-enum fields, filtering unknown enum names while keeping valid unknown numerics as EnumValue::Unknown. The lenient behavior std builds already had is now consistent across field shapes, with no_std coverage added to CI.
registry: any registry type name anthropics/buffa
Any registry lookups now resolve by protobuf full name when an incoming type URL carries a different prefix, since those prefixes are application-defined and exact-URL matching alone can miss a registered message; exact URL matches still win. JSON and text registries gained type-name indexes, with custom-prefix lookups tested and the original URL preserved through JSON round trips.