Skip to content

Harden project lifecycle, CLI outcomes, and release verification - #149

Merged
LunaStev merged 12 commits into
wavefnd:masterfrom
LunaStev:patch/production-hardening
Sep 27, 2026
Merged

LunaStev merged 12 commits into
wavefnd:masterfrom
LunaStev:patch/production-hardening

Conversation

@LunaStev

@LunaStev LunaStev commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Summary

Harden project initialization, dependency checkout reuse, subprocess outcomes, compiler installation, and release verification. Interrupted or failed work preserves existing project data; automation gets typed exit categories and a separate JSONL report without changing program stdio.

Why

Production use needs recoverable filesystem changes, bounded noninteractive Git operations, credential-safe persistent state, and verifiable compiler/release artifacts. This coordinated change also completes the approved CLI outcome contract so scripts can distinguish a Vex failure from the same exit code returned by a user program.

Behavior

  • Reject invalid package names before creating state. Initialize through staging and a durable recovery journal; preserve existing files and stop recovery when owned files have been edited or replaced.
  • Use canonical SHA-256 checkout directory names with lazy legacy migration. Reuse clean, detached, exactly pinned checkouts without staging copies or extra backups. Preserve path identity across graph traversal order, create missing empty lockfiles on ordinary/offline fetch, and test source replacement/removal and SHA-256 Git repositories.
  • Handle Windows long file/pack paths with command-scoped Git settings, relative repository selection, and private initialization for deep candidates. Test SHA-1/SHA-256 fetch, update, locked/offline reuse, and fresh pinned restoration. Windows checkout directories (including staging) are bounded to 240 UTF-16 units; longer paths fail with relocation guidance. Explicit core.longpaths=false can still cause upstream Git path errors or false dirty reports; diagnostics explain the setting while preserving user configuration, checkout files, and lockfiles.
  • Supervise Git/compiler processes with cancellation, bounded captured output, and Git deadlines/prompt suppression. Preserve runtime stdio/TTY and child exit codes, with Unix signal translation. Windows uses suspended creation and Job Objects.
  • Return Vex codes 1/2/3/4/5/124/130 for internal/usage/resolution/compiler/environment/timeout/cancellation failures. vex --message-file <new-path> <command> writes schema-1 JSONL with origin: vex|program; it never overwrites existing files. Dry-run validates the destination without creating the report. Reporting failures before runtime stop Vex; failures after execution warn and preserve the program outcome.
  • Accept transport credentials while removing authentication from rendered Git sources, new lockfiles, checkout origins, and diagnostics. Historical credential-bearing lockfiles require an unlocked migration; locked mode preserves their bytes and errors. Transaction journal v2 stores the old lock hash rather than its contents.
  • Install official compiler artifacts through checksum verification, available GitHub provenance verification, bounded safe extraction, exact version checks, immutable generations, and an atomic current pointer. Downloaded installer scripts require explicit --script-fallback.
  • Bound structured-input parsing and exercise malformed inputs. Add OSV auditing with distinct finding/audit-failure outcomes and expiring exceptions, scheduled audits and dependency updates, immutable Action pins, and release provenance generation/verification.

Compatibility and recovery details: production hardening, CLI contract, and roadmap. Existing lockfile v2/v3 readers remain supported. Locked/dry-run operations do not migrate checkout paths; backups and generations have no automatic GC. Rust remains 1.96.0. Git/path dependencies remain the supported source model.

Related implementation and acceptance tracking: #21, #33, #24, #110, #79, #147, #146, #86, #92, #90, #148, #81, #124, #138, #80, #96, #68, #69, #70, #75, #99. These references intentionally do not auto-close the issues; native CI and remaining acceptance must be assessed individually. The bounded parser corpus is not exhaustive fuzzing coverage.

Validation

  • cargo fmt --check
  • cargo test --workspace --locked
  • cargo clippy --workspace --locked --all-targets -- -D warnings
  • cargo build --workspace --locked
  • python3 x.py check: 116 Rust tests and 29 Python tests passed. One ignored subprocess fixture is explicitly exercised by its parent test.
  • Windows GNU, Linux ARM64, and Linux RISC-V workspace/all-targets cross checks; additional Windows GNU Clippy with -D warnings.
  • Local Wave development compiler package/re-export/private-access/locked/offline smoke; PTY + JSONL input/output and foreground ownership restoration.
  • Linux amd64 release build/package, full version/help smoke, archive checksum, and release JSONL smoke.
  • Isolated official Wave v0.2.0-pre-beta artifact installation with published checksum verification. Its provenance endpoint reported no attestations; this is not a signature claim.
  • OSV observation: 102 external packages, no findings or exceptions, 2026-09-27T10:25:43Z; Cargo.lock SHA-256 5659baf56e4b71c40e3d1446bf5d581dc7f8cb2bd5d11f9d8dbe14546bf62fc3.
  • All eight required PR CI jobs passed on 45eaa76239aad5513a1f50e36099c75c9ccc6a33, including native Windows x64 and macOS x64/arm64: CI run 36318907018. Cross checks are recorded separately above.

The release workflow has not been dispatched and no release/tag was created. Required real-compiler CI (#66/#131) remains deferred until a compatible official Wave release is validated; the tested official archive lacks canonical package imports, and the local development compiler is only manual evidence.

Checklist

  • The change is one coordinated production-hardening bundle targeting wavefnd/Vex:master.
  • User-facing behavior and recovery instructions are documented.
  • Dependency changes preserve lockfile reproducibility.
  • --locked and --offline behavior is covered by regression tests.
  • No raw wavec flags were added to the Vex CLI.
  • New commits include a DCO Signed-off-by: line.

Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
@LunaStev
LunaStev merged commit 63d0836 into wavefnd:master Sep 27, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant