Key hardening changes:
- Config validation now rejects paths.source: . and paths.assets: ., so source/asset roots cannot
resolve to the repository root.
- apply-hak-manifest now refuses to run when paths.source is unset or unsafe, instead of potentially
writing under a root-level module/.
- Inline flags across utility parsers now reject empty values consistently, e.g. --dataset=, --hak=,
--endpoint=, --output=.
- build-changelog now supports --flag=value inline syntax like the other utilities.
When that flag is used, sow-tools:
- collects only the assets referenced by that manifest subset
- skips full-project chunk planning for the per-archive run
- reconstructs just the requested archive chunks from the manifest
Root cause:
build-haks --archive ... was still collecting content requirements for
the entire asset inventory before chunk filtering.
So even when building sow_over_01, it demanded downloaded LFS objects
from unrelated groups like appr.
sow-tools no longer relies on git lfs ls-files --json for planning. It
now parses the checked-out LFS pointer files directly, so split sizing
and content_hash use the real LFS oid and size.
In build.go, build-haks now does conservative chunk reuse instead of
wiping all generated HAKs up front. It plans chunks as before, computes
a deterministic per-chunk content_hash, reuses an existing .hak only
when the prior manifest entry and on-disk archive still match, rebuilds
only changed chunks, and deletes only stale generated HAKs that fall out
of the new plan. I added coverage for unchanged reuse and selective
rebuilds in pipeline_test.go, and go test ./... passes in sow-tools.
In sow-tools, extract now behaves like a real sync by default: it
overwrites changed extracted files, removes stale extracted files that
no longer exist in the built archives, and normalizes extracted resource
filenames to lowercase. I also made validation warn on uppercase
resource filenames so mixed-case names like I_ELVENCHAIN are surfaced
instead of quietly lingering. The extract command output now includes
overwritten and removed counts too.