Git and CI

Windows · macOS · Android · home

Two directions: keeping offsets from this server inside your own repository, and publishing verified offsets to this server from your own pipeline.

Keep verified offsets in a repository

A GitHub Actions workflow that commits the live build's verified offsets whenever they change. Forgejo and Gitea Actions read the same file from .forgejo/workflows/.

# .github/workflows/sync-offsets.yml
name: sync-offsets
on:
  schedule: [{ cron: "*/15 * * * *" }]
  workflow_dispatch:
permissions:
  contents: write
jobs:
  sync:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Pull verified offsets for the live build
        run: |
          set -euo pipefail
          BASE=https://rbxoffsets.com
          v=$(curl -fsS "$BASE/api/v1/windows/version.txt")
          mkdir -p "offsets/$v"
          for f in offsets.hpp offsets.json; do
            curl -fsSL -o "offsets/$v/$f" "$BASE/api/v1/windows/offsets/$v/verified/$f"
          done
          git config user.name  "offsets-sync"
          git config user.email "offsets-sync@users.noreply.github.com"
          git add offsets
          git diff --cached --quiet || git commit -m "offsets: $v"
          git push

The step fails — and the workflow shows red — when the live build has no verified set yet. That is intentional; drop /verified from the URL to accept default offsets too.

Fail a build that ships stale offsets

A check for a repository that vendors offsets: it compares the build the header was dumped from against what is live.

#!/usr/bin/env bash
# ci/check-offsets.sh
set -euo pipefail
live=$(curl -fsS https://rbxoffsets.com/api/v1/windows/version.txt)
have=$(jq -r '."Roblox Version"' third_party/offsets/offsets.json)
if [ "$live" != "$have" ]; then
  echo "offsets are for $have, but $live is live" >&2
  exit 1
fi

Publish verified offsets from your pipeline

Dump against the upcoming build, so the verified set is ready before most players have it. Store the token as a repository secret named RBXOFFSETS_TOKEN.

# .github/workflows/publish-offsets.yml
name: publish-offsets
on:
  workflow_dispatch:
  schedule: [{ cron: "*/10 * * * *" }]
jobs:
  publish:
    runs-on: windows-latest
    steps:
      - uses: actions/checkout@v4
      - name: Find the build to dump
        id: build
        shell: bash
        run: |
          next=$(curl -fsS https://rbxoffsets.com/api/v1/windows/upcoming.txt || true)
          echo "version=${next:-$(curl -fsS https://rbxoffsets.com/api/v1/windows/version.txt)}" >> "$GITHUB_OUTPUT"
      - name: Download that build
        shell: bash
        run: curl -fL -o RobloxApp.zip "https://rbxoffsets.com/download/windows/${{ steps.build.outputs.version }}"
      - name: Dump
        run: ./your-dumper.exe RobloxApp.zip --out dump
      - name: Publish as verified
        shell: bash
        env:
          TOKEN: ${{ secrets.RBXOFFSETS_TOKEN }}
        run: |
          cd dump
          curl -fsS -X POST -H "Authorization: Bearer $TOKEN" \
            -F offsets.json=@offsets.json -F offsets.hpp=@offsets.hpp \
            -F offsets.cs=@offsets.cs -F offsets.txt=@offsets.txt \
            -F verified_by=ci -F "notes=run ${{ github.run_id }}" \
            "https://rbxoffsets.com/internal/offsets/windows/${{ steps.build.outputs.version }}"

An upload whose offsets.json names a different build than the URL is refused, so a race between "find the build" and "publish" cannot file a dump under the wrong version.

Without a CI system

git clone https://your.git.host/you/offsets.git && cd offsets
v=$(curl -fsS https://rbxoffsets.com/api/v1/windows/version.txt)
curl -fsSL -o offsets.hpp "https://rbxoffsets.com/api/v1/windows/offsets/$v/hpp"
git commit -am "offsets: $v" && git push