Harden project lifecycle, CLI outcomes, and release verification - #149
Merged
Merged
Conversation
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
Signed-off-by: LunaStev <luna@lunastev.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Harden project initialization, dependency checkout reuse, subprocess outcomes, compiler installation, and release verification. Interrupted or failed work preserves existing project data; automation gets typed exit categories and a separate JSONL report without changing program stdio.
Why
Production use needs recoverable filesystem changes, bounded noninteractive Git operations, credential-safe persistent state, and verifiable compiler/release artifacts. This coordinated change also completes the approved CLI outcome contract so scripts can distinguish a Vex failure from the same exit code returned by a user program.
Behavior
core.longpaths=falsecan still cause upstream Git path errors or false dirty reports; diagnostics explain the setting while preserving user configuration, checkout files, and lockfiles.vex --message-file <new-path> <command>writes schema-1 JSONL withorigin: vex|program; it never overwrites existing files. Dry-run validates the destination without creating the report. Reporting failures before runtime stop Vex; failures after execution warn and preserve the program outcome.--script-fallback.Compatibility and recovery details: production hardening, CLI contract, and roadmap. Existing lockfile v2/v3 readers remain supported. Locked/dry-run operations do not migrate checkout paths; backups and generations have no automatic GC. Rust remains 1.96.0. Git/path dependencies remain the supported source model.
Related implementation and acceptance tracking: #21, #33, #24, #110, #79, #147, #146, #86, #92, #90, #148, #81, #124, #138, #80, #96, #68, #69, #70, #75, #99. These references intentionally do not auto-close the issues; native CI and remaining acceptance must be assessed individually. The bounded parser corpus is not exhaustive fuzzing coverage.
Validation
cargo fmt --checkcargo test --workspace --lockedcargo clippy --workspace --locked --all-targets -- -D warningscargo build --workspace --lockedpython3 x.py check: 116 Rust tests and 29 Python tests passed. One ignored subprocess fixture is explicitly exercised by its parent test.-D warnings.5659baf56e4b71c40e3d1446bf5d581dc7f8cb2bd5d11f9d8dbe14546bf62fc3.45eaa76239aad5513a1f50e36099c75c9ccc6a33, including native Windows x64 and macOS x64/arm64: CI run 36318907018. Cross checks are recorded separately above.The release workflow has not been dispatched and no release/tag was created. Required real-compiler CI (#66/#131) remains deferred until a compatible official Wave release is validated; the tested official archive lacks canonical package imports, and the local development compiler is only manual evidence.
Checklist
wavefnd/Vex:master.--lockedand--offlinebehavior is covered by regression tests.wavecflags were added to the Vex CLI.Signed-off-by:line.