Files
hemx/PLAN.md
T
slhx agent e7ca6d2350 test(wasm): close mutation package gate
Run browser-backed mutest sequentially without a parent jobserver, disable Firefox background work, batch replay projections while preserving ordered application, and elect a 250 ms budget for the durable 64-command browser fixture. All four hemx-wasm shards pass with 59 mutants and no survivors, closing the mutation matrix.

req: test/004

req: test/020

req: test/021

req: performance/005

req: performance/007

req: v1_release/006
2026-07-17 17:11:19 +02:00

7.1 KiB
Raw Blame History

Active frontier — v1 production readiness

Parent outcome

  • User value: Rust teams can adopt hemx v1 knowing its public contracts, failure recovery, compatibility, dependency policy, and release proof are explicit and reproducible.
  • State: In progress — the product and representative runtime/browser/performance/security paths are implemented, but v1 production readiness is not yet closed.
  • Blocked by: the repository owner must approve a distribution license policy before the legal release gate can close; this does not block mutation hardening or local release verification.
  • Non-goals: no new framework surface, second wire format, WASM runtime decoder, deployment, publication, signing, store submission, or feature expansion.
  • Proof: every child below is done; docs/v1-readiness.md reports GO without contradicting REQUIREMENTS.md; the tree is committed and clean.

1. Checkpoint the current robustness slice

  • State: Done — committed as the current robustness slice after full workspace, focused compile-fail, requirements-reference, formatting, and check proof.
  • User value: users receive one explicit typed EffectBatch codec and stronger fail-closed form, sync, host, WASM, macro, test-harness, and generated-contract boundaries without parallel magic.
  • Build: review the current diff as one coherent behavior/requirements slice; retain the canonical non-WASM EffectBatch codec and remove the duplicate postcard batch API; keep only mutation-driven tests and simplifications that prove public behavior; run the full local test authority; commit the slice.
  • Blocked by: none.
  • Proof: cargo run -p hemx-xtask -- test, cargo fmt --check, cargo check --workspace, redgate list, and redgate refs pass; git diff --check is clean; the focused mutest receipts for the effect codec, hemx, hemx-host, hemx-js, hemx-wasm, hemx-sync, hemx-sync-macros, hemx-test public helpers, and hemx-axum form/SSE codecs contain no missed mutants; one Conventional Commit records the requirement IDs.

2. Make mutation testing a reproducible release gate

  • State: Done — the package-native capped xtask entry point rejects unknown packages and invalid shards, propagates mutest failure, and every mutation-applicable library/proc-macro package passes its complete gate or deterministic shard set with no unexplained survivor.
  • User value: maintainers can run one bounded repository command and trust that meaningful Rust logic across every mutation-applicable library is either killed or explicitly justified.
  • Build: add a capped hemx-xtask mutation command that invokes /opt/repositories/mutest/mutest through package-native test targets rather than the broken workspace-wide example path; enumerate only current mutation-applicable library/proc-macro packages; finish adversarial tests or simplify code until every survivor is classified; keep equivalent, invariant-only, and infrastructure-inapplicable classifications inspectable and minimal; document the exact local release command in the existing readiness surface.
  • Blocked by: none. hemx-lsp is binary-only and deliberately outside the mutation-applicable library/proc-macro set elected by test/020; its package tests remain in workspace verification. The runner creates first-use shard output parents, accepts validated one-based shards, maps them to native zero-based shards, uses shard-specific output, grants compiler probes a 120-second floor, and preserves the unsharded gate. Browser-backed hemx-wasm runs one mutest worker without a parent jobserver, preventing nested Cargo/Firefox deadlock while preserving the detected Cargo budget; its four shards pass with 59 mutants (52 caught, 7 unviable) after replay projections were batched without changing ordered effect application, Firefox background work was disabled, and the explicit 64-command debug-browser replay budget was set to 250 ms. The complete hemx (30 mutants), hemx-host (76), hemx-sync (164), hemx-sync-macros (33), hemx-axum (470), hemx-build (1,304), and hemx-derive (480) gates or deterministic shard sets pass, alongside the previously clean hemx-core, hemx-js, and hemx-test gates.
  • Proof: the new xtask mutation command exits zero within its documented bound, covers each applicable package, emits no unexplained missed mutant, and a deliberate adjacent mutation makes it fail. cargo run -p hemx-xtask -- test remains green. req: test/020 req: test/021

3. Elect and enforce the release license policy

  • State: Needs decision
  • User value: adopters can legally evaluate and redistribute hemx with a machine-checked dependency license boundary.
  • Build: owner chooses the repository distribution license and accepted dependency licenses; add the corresponding root license file(s) and minimal deny.toml; classify workspace crates and the current dependency set; run strict license, advisory, and source checks; reject unknown/unlicensed dependencies rather than silently broadening policy.
  • Blocked by: owner legal decision: choose the repository license and whether weak-copyleft dependencies are acceptable. Current dependency licenses observed by cargo deny list include Apache-2.0, Apache-2.0 WITH LLVM-exception, BSD-3-Clause, BSL-1.0, MIT, Unicode-3.0, Unlicense, plus unlicensed workspace packages because the repository has no elected license.
  • Proof: cargo deny check licenses advisories sources exits zero from repository configuration; every allowed license is explicit; the repository license is visible at the root; adding a disallowed/unlicensed fixture fails the gate. req: security/007 req: v1_release/006

4. Issue the final v1 GO/NO-GO decision

  • State: Blocked by slices 13
  • User value: users get an honest release candidate whose documented support, recovery, accessibility, performance, examples, and operational behavior match what was actually proven.
  • Build: rerun the complete local release matrix from docs/v1-readiness.md, including mutation and license gates; verify the pinned Rust/browser/WASM/Axum compatibility matrix and migration fixture; run browser, offline/reconnect, mixed-deploy recovery, accessibility, security, performance, docs, and canonical-example proofs; independently audit requirement-to-proof coverage and README/readiness contradictions; fix only release-blocking defects; mark GO only when no P0/P1 or unexplained gate failure remains.
  • Blocked by: slices 13; publishing/deployment authority remains separate and is not required for a local GO decision.
  • Proof: all commands in docs/v1-readiness.md pass from a clean checkout within documented bounds; redgate list and redgate refs pass; known installed redgate health/lint corpus-format warnings are either resolved or accurately documented rather than hidden; docs/v1-readiness.md says GO and names zero open release blockers; independent contradiction review agrees. req: v1_release/001 req: v1_release/002 req: v1_release/003 req: v1_release/004 req: v1_release/005 req: v1_release/006 req: v1_release/007 req: v1_release/008 req: v1_release/009 req: v1_release/010