df9f8f16fb
Fail closed on malformed symbol lines, prove sorted deduplicated component discovery and component filtering, exclude ordinary functions from handler registration, and emit diagnostics through quoted tokens without string reparsing. req: diagnostics/003 req: component/003 req: derive_handler/003 req: test/020 req: test/021 req: test/022 req: test/023
7.3 KiB
7.3 KiB
Active frontier — v1 production readiness
Parent outcome
- User value: Rust teams can adopt hemx v1 knowing its public contracts, failure recovery, compatibility, dependency policy, and release proof are explicit and reproducible.
- State: In progress — the product and representative runtime/browser/performance/security paths are implemented, but v1 production readiness is not yet closed.
- Blocked by: the repository owner must approve a distribution license policy before the legal release gate can close; this does not block mutation hardening or local release verification.
- Non-goals: no new framework surface, second wire format, WASM runtime decoder, deployment, publication, signing, store submission, or feature expansion.
- Proof: every child below is done;
docs/v1-readiness.mdreports GO without contradictingREQUIREMENTS.md; the tree is committed and clean.
1. Checkpoint the current robustness slice
- State: Done — committed as the current robustness slice after full workspace, focused compile-fail, requirements-reference, formatting, and check proof.
- User value: users receive one explicit typed
EffectBatchcodec and stronger fail-closed form, sync, host, WASM, macro, test-harness, and generated-contract boundaries without parallel magic. - Build: review the current diff as one coherent behavior/requirements slice; retain the canonical non-WASM
EffectBatchcodec and remove the duplicate postcard batch API; keep only mutation-driven tests and simplifications that prove public behavior; run the full local test authority; commit the slice. - Blocked by: none.
- Proof:
cargo run -p hemx-xtask -- test,cargo fmt --check,cargo check --workspace,redgate list, andredgate refspass;git diff --checkis clean; the focused mutest receipts for the effect codec,hemx,hemx-host,hemx-js,hemx-wasm,hemx-sync,hemx-sync-macros,hemx-testpublic helpers, andhemx-axumform/SSE codecs contain no missed mutants; one Conventional Commit records the requirement IDs.
2. Make mutation testing a reproducible release gate
- State: In progress — the package-native capped xtask entry point is reachable, rejects unknown packages and invalid shards, propagates mutest failure, and mutation-tests
hemx-axum,hemx-build,hemx-core,hemx-js, and the fullhemx-testpackage cleanly; full package closure remains. - User value: maintainers can run one bounded repository command and trust that meaningful Rust logic across every mutation-applicable library is either killed or explicitly justified.
- Build: add a capped
hemx-xtaskmutation command that invokes/opt/repositories/mutest/mutestthrough package-native test targets rather than the broken workspace-wide example path; enumerate only current mutation-applicable library/proc-macro packages; finish adversarial tests or simplify code until every survivor is classified; keep equivalent, invariant-only, and infrastructure-inapplicable classifications inspectable and minimal; document the exact local release command in the existing readiness surface. - Blocked by: none; broad survivors currently remain in
hemx-lspoutside already-clean focused contracts. The xtask mutation runner now creates shard output parents before invoking mutest, fixing first-use failure for newly sharded packages. All eight deterministichemx-deriveshards pass: 480 mutants total, 393 caught and 87 unviable, including final shard8/8with 54 mutants (42 caught, 12 unviable) after fail-closed malformed symbol-line handling, exact sorted/deduplicated component discovery, component filtering, non-handler exclusion, and direct quoted compile diagnostics. The mutation entry point accepts validated one-basedSHARD/TOTALoperands, maps them to native zero-based shards, uses shard-specific output directories, grants repo-owned compiler probes a 120-second floor, and preserves the unsharded gate. All eight deterministichemx-buildshards now pass: 1,304 mutants total, 1,070 caught and 234 unviable, including final shard8/8with 159 mutants (139 caught, 20 unviable). The complete 470-mutanthemx-axumpackage gate passes with 262 caught and 208 unviable after public page/form/multipart/registry/response/runtime proofs and narrow classification of infallible header parsing and streamed multipart unwrap-equivalent mutants. - Proof: the new xtask mutation command exits zero within its documented bound, covers each applicable package, emits no unexplained missed mutant, and a deliberate adjacent mutation makes it fail.
cargo run -p hemx-xtask -- testremains green. req: test/020 req: test/021
3. Elect and enforce the release license policy
- State: Needs decision
- User value: adopters can legally evaluate and redistribute hemx with a machine-checked dependency license boundary.
- Build: owner chooses the repository distribution license and accepted dependency licenses; add the corresponding root license file(s) and minimal
deny.toml; classify workspace crates and the current dependency set; run strict license, advisory, and source checks; reject unknown/unlicensed dependencies rather than silently broadening policy. - Blocked by: owner legal decision: choose the repository license and whether weak-copyleft dependencies are acceptable. Current dependency licenses observed by
cargo deny listinclude Apache-2.0, Apache-2.0 WITH LLVM-exception, BSD-3-Clause, BSL-1.0, MIT, Unicode-3.0, Unlicense, plus unlicensed workspace packages because the repository has no elected license. - Proof:
cargo deny check licenses advisories sourcesexits zero from repository configuration; every allowed license is explicit; the repository license is visible at the root; adding a disallowed/unlicensed fixture fails the gate. req: security/007 req: v1_release/006
4. Issue the final v1 GO/NO-GO decision
- State: Blocked by slices 1–3
- User value: users get an honest release candidate whose documented support, recovery, accessibility, performance, examples, and operational behavior match what was actually proven.
- Build: rerun the complete local release matrix from
docs/v1-readiness.md, including mutation and license gates; verify the pinned Rust/browser/WASM/Axum compatibility matrix and migration fixture; run browser, offline/reconnect, mixed-deploy recovery, accessibility, security, performance, docs, and canonical-example proofs; independently audit requirement-to-proof coverage and README/readiness contradictions; fix only release-blocking defects; mark GO only when no P0/P1 or unexplained gate failure remains. - Blocked by: slices 1–3; publishing/deployment authority remains separate and is not required for a local GO decision.
- Proof: all commands in
docs/v1-readiness.mdpass from a clean checkout within documented bounds;redgate listandredgate refspass; known installedredgate health/lintcorpus-format warnings are either resolved or accurately documented rather than hidden;docs/v1-readiness.mdsays GO and names zero open release blockers; independent contradiction review agrees. req: v1_release/001 req: v1_release/002 req: v1_release/003 req: v1_release/004 req: v1_release/005 req: v1_release/006 req: v1_release/007 req: v1_release/008 req: v1_release/009 req: v1_release/010