<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: wuddleko</title>
    <description>The latest articles on DEV Community by wuddleko (@wuddleko).</description>
    <link>https://dev.to/wuddleko</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4154596%2Fc7a6f510-76e3-414a-a1da-ddcb04c767a0.png</url>
      <title>DEV Community: wuddleko</title>
      <link>https://dev.to/wuddleko</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/wuddleko"/>
    <language>en</language>
    <item>
      <title>Generated files lie until you rerun the generator</title>
      <dc:creator>wuddleko</dc:creator>
      <pubDate>Thu, 01 Oct 2026 11:58:25 +0000</pubDate>
      <link>https://dev.to/wuddleko/generated-files-lie-until-you-rerun-the-generator-20le</link>
      <guid>https://dev.to/wuddleko/generated-files-lie-until-you-rerun-the-generator-20le</guid>
      <description>&lt;p&gt;Someone changes a protobuf field's type, or reuses a field number. The &lt;code&gt;.proto&lt;/code&gt; is reviewed and merged. Nobody ran &lt;code&gt;buf generate&lt;/code&gt;. CI is green: the Go still type-checks against the &lt;code&gt;api.pb.go&lt;/code&gt; that was already in the tree. A client built from the new proto talks to a server built from the old one, and the compiler never said a word.&lt;/p&gt;

&lt;p&gt;That's the tax on committing generated code. What's in Git is a snapshot of some past run. The thing that actually defines those files is the command that wrote them.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/wuddleko/genguard" rel="noopener noreferrer"&gt;genguard&lt;/a&gt; re-runs that command and fails if the outputs don't match &lt;code&gt;HEAD&lt;/code&gt;. It doesn't install your generators, and it doesn't commit anything. If you already check in protobuf, sqlc, OpenAPI, &lt;code&gt;go generate&lt;/code&gt;, or a Makefile target, this is the gate. In CI, or with &lt;code&gt;--isolated&lt;/code&gt;, it answers whether a fresh clone of this commit would produce the same files. A local &lt;code&gt;check&lt;/code&gt; without &lt;code&gt;--isolated&lt;/code&gt; writes your working tree.&lt;/p&gt;

&lt;h2&gt;
  
  
  The script you'd write if you were being careful
&lt;/h2&gt;

&lt;p&gt;Most people start with &lt;code&gt;buf generate &amp;amp;&amp;amp; git diff --exit-code gen/&lt;/code&gt;. That's the short version. The careful one looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;set&lt;/span&gt; &lt;span class="nt"&gt;-euo&lt;/span&gt; pipefail
&lt;span class="nb"&gt;rm&lt;/span&gt; &lt;span class="nt"&gt;-rf&lt;/span&gt; gen
buf generate
git diff &lt;span class="nt"&gt;--exit-code&lt;/span&gt; HEAD &lt;span class="nt"&gt;--&lt;/span&gt; gen
&lt;span class="nb"&gt;test&lt;/span&gt; &lt;span class="nt"&gt;-z&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;git ls-files &lt;span class="nt"&gt;--others&lt;/span&gt; &lt;span class="nt"&gt;--exclude-standard&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; gen&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;HEAD&lt;/code&gt;, not the index, because that's what CI will check out. The &lt;code&gt;ls-files&lt;/code&gt; line catches a file the generator started writing. The &lt;code&gt;rm -rf&lt;/code&gt; is there so a file it stopped writing doesn't sit around looking identical to the last commit.&lt;/p&gt;

&lt;p&gt;On a clean CI checkout, that script catches the stale &lt;code&gt;api.pb.go&lt;/code&gt; above. It's enough for one generator. The rest of this post is why you still don't want to live in that script: skip logic, pinning the generator so CI isn't a different &lt;code&gt;buf&lt;/code&gt; than your laptop, and a wipe you can actually aim.&lt;/p&gt;

&lt;h2&gt;
  
  
  Skipping a generator is the part nobody wants to maintain
&lt;/h2&gt;

&lt;p&gt;The careful script always runs &lt;code&gt;buf generate&lt;/code&gt;. That's fine until the run takes forty seconds and the PR only touched SQL.&lt;/p&gt;

&lt;p&gt;A skip you can trust is more than &lt;code&gt;git diff origin/main -- proto/&lt;/code&gt;. You need the merge-base of &lt;code&gt;HEAD&lt;/code&gt; and that ref, not whatever &lt;code&gt;main&lt;/code&gt; happens to be now, and you also have to compare against &lt;code&gt;HEAD&lt;/code&gt;. You shouldn't skip a group that never declared inputs. A bad ref should fail the job before anything gets deleted. And you still have to re-run if any of these changed:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;outputs&lt;/li&gt;
&lt;li&gt;the config file&lt;/li&gt;
&lt;li&gt;a listed output file is missing&lt;/li&gt;
&lt;li&gt;something under those paths is untracked&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Then you copy that predicate for sqlc, and again in the next service. People don't finish that script. Either every generator runs every time, or someone writes a path filter, misses a config change, and ships stale stubs.&lt;/p&gt;

&lt;p&gt;genguard keeps the path lists next to the generated files and does the skip once. &lt;code&gt;--since origin/main&lt;/code&gt; skips a group whose inputs, outputs, and config still match both the merge-base of that ref and &lt;code&gt;HEAD&lt;/code&gt;. &lt;code&gt;--all&lt;/code&gt; finds every &lt;code&gt;genguard.yaml&lt;/code&gt; in the repo.&lt;/p&gt;

&lt;h2&gt;
  
  
  CI is a different &lt;code&gt;buf&lt;/code&gt; than your laptop
&lt;/h2&gt;

&lt;p&gt;The most common false drift isn't a forgotten regenerate. It's CI running a different generator version than you did:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;tools&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;buf&lt;/span&gt;
    &lt;span class="na"&gt;version&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;1.32.0&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;sqlc&lt;/span&gt;
    &lt;span class="na"&gt;version&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;1.27.0&lt;/span&gt;

&lt;span class="na"&gt;clean&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;
&lt;span class="na"&gt;groups&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;protobuf&lt;/span&gt;
    &lt;span class="na"&gt;command&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;buf generate&lt;/span&gt;
    &lt;span class="na"&gt;tools&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;buf&lt;/span&gt;&lt;span class="pi"&gt;]&lt;/span&gt;
    &lt;span class="na"&gt;inputs&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;proto/&lt;/span&gt;
    &lt;span class="na"&gt;outputs&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;gen/&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;sqlc&lt;/span&gt;
    &lt;span class="na"&gt;command&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;sqlc generate&lt;/span&gt;
    &lt;span class="na"&gt;tools&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;[&lt;/span&gt;&lt;span class="nv"&gt;sqlc&lt;/span&gt;&lt;span class="pi"&gt;]&lt;/span&gt;
    &lt;span class="na"&gt;inputs&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;queries/&lt;/span&gt;
    &lt;span class="na"&gt;outputs&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;internal/db/&lt;/span&gt;
    &lt;span class="na"&gt;clean&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;false&lt;/span&gt;  &lt;span class="c1"&gt;# hand-written files live here&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Use &lt;code&gt;clean: true&lt;/code&gt; only where &lt;code&gt;outputs&lt;/code&gt; hold nothing but generated files. &lt;code&gt;genguard check&lt;/code&gt; runs the groups in order and only looks at those paths against &lt;code&gt;HEAD&lt;/code&gt;. A missing or mismatched tool fails the group before &lt;code&gt;clean&lt;/code&gt; and before the generator.&lt;/p&gt;

&lt;p&gt;When the stubs are stale, you get this, then a &lt;code&gt;git diff&lt;/code&gt; of the file:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Summary
  protobuf: drift (1 modified); buf 1.32.0
1 group: 0 ok, 1 drift, 0 error

Drift
[modified] protobuf: gen/api.pb.go

error: 1 generated path drifted;
commit the generator output or fix the command
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Leftover files, and a wipe that won't take &lt;code&gt;.git&lt;/code&gt; with it
&lt;/h2&gt;

&lt;p&gt;The type-change above shows up in &lt;code&gt;git diff HEAD&lt;/code&gt;. This one doesn't. You delete &lt;code&gt;old.proto&lt;/code&gt;, or rename it, or point the generator at a new output path. The generator stops writing &lt;code&gt;old.pb.go&lt;/code&gt;. The file stays tracked, still compiles, still sits on the public API. &lt;code&gt;git diff HEAD -- gen&lt;/code&gt; is empty because that file didn't change.&lt;/p&gt;

&lt;p&gt;You only catch it if you delete &lt;code&gt;gen/&lt;/code&gt; first. With &lt;code&gt;clean: true&lt;/code&gt;, a leftover file shows up like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[missing] protobuf: gen/old.pb.go
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Skip the wipe, and the leftover is invisible. Do a blanket &lt;code&gt;rm -rf&lt;/code&gt;, and a failed &lt;code&gt;buf generate&lt;/code&gt; leaves you with an empty directory in the checkout you were working in.&lt;/p&gt;

&lt;p&gt;genguard will wipe when you set &lt;code&gt;clean: true&lt;/code&gt;, and only the paths you listed. It refuses &lt;code&gt;.git&lt;/code&gt;, the config file, a symlink, or anything outside the config directory. It doesn't put the files back if the command dies. &lt;code&gt;--isolated&lt;/code&gt; runs the same check in a temporary worktree and leaves your checkout alone.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it won't do
&lt;/h2&gt;

&lt;p&gt;It won't install &lt;code&gt;buf&lt;/code&gt; or put it on &lt;code&gt;PATH&lt;/code&gt;. The &lt;code&gt;tools&lt;/code&gt; pin fails a mismatch; it doesn't fetch the binary. The GitHub Action is the same: it installs genguard, not your generators.&lt;/p&gt;

&lt;p&gt;If the generator isn't bit-stable, &lt;code&gt;check&lt;/code&gt; will fail every time. That's the generator, not the checker.&lt;/p&gt;

&lt;p&gt;It won't tell you the rest of the working tree is dirty. It only looks at &lt;code&gt;outputs&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;And it won't commit. You regenerate locally, commit, push. CI proves the snapshot.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick start
&lt;/h2&gt;

&lt;p&gt;This is v0.7.0. The project is pre-1.0; flags have moved before.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;go &lt;span class="nb"&gt;install &lt;/span&gt;github.com/wuddleko/genguard/cmd/genguard@v0.7.0
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Copy &lt;a href="https://github.com/wuddleko/genguard/blob/main/examples/buf.yaml" rel="noopener noreferrer"&gt;examples/buf.yaml&lt;/a&gt; to &lt;code&gt;genguard.yaml&lt;/code&gt; next to the generated directory, not inside it, and fix the paths. Then:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;genguard check
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A match prints &lt;code&gt;Generated files match the generators.&lt;/code&gt; and exits 0. Drift exits 1 with the paths and a diff. Bad config, Git, or a crashed generator exits 2.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;uses&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;actions/checkout@v4&lt;/span&gt;
  &lt;span class="na"&gt;with&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;fetch-depth&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;   &lt;span class="c1"&gt;# needed for --since&lt;/span&gt;
&lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;uses&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;wuddleko/genguard@v0.7.0&lt;/span&gt;
  &lt;span class="na"&gt;with&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;all&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="kc"&gt;true&lt;/span&gt;
    &lt;span class="na"&gt;since&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;origin/main&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Put &lt;code&gt;buf&lt;/code&gt;, &lt;code&gt;sqlc&lt;/code&gt;, and the rest on &lt;code&gt;PATH&lt;/code&gt; in that job. Per-tool setup is in &lt;a href="https://github.com/wuddleko/genguard/blob/main/docs/ci.md" rel="noopener noreferrer"&gt;docs/ci.md&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/wuddleko/genguard" rel="noopener noreferrer"&gt;github.com/wuddleko/genguard&lt;/a&gt; — more templates in &lt;code&gt;examples/&lt;/code&gt;, internals in &lt;a href="https://github.com/wuddleko/genguard/blob/main/docs/design.md" rel="noopener noreferrer"&gt;docs/design.md&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>go</category>
      <category>git</category>
      <category>ci</category>
      <category>devops</category>
    </item>
  </channel>
</rss>
