Repository navigation
feat: validate native configuration with a bundled pure compiler - #154
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Native configuration now has a standalone Rust owner and an explicit offline validation command:
hack config validate --file <JSON> [--profile <names>] [--json]. It produces normalized symbolic plans and deterministic semantic hashes, or fixed redacted diagnostics with authored locations. The CLI checks the compiler protocol before sending input, bounds its I/O, strips inherited credentials, and reaps its child on timeout or interruption.This foundation supports services/jobs, basic image/build selection, commands, source/storage mounts, environment directives, profiles, dependencies and readiness. Generated JSON Schema and TypeScript DTOs share the Rust types. Unsupported fields refuse. Runtime discovery, project migration, secret admission and backend execution are still outside this command; successful validation does not establish that a project can run.
Future native candidate bundles carry a signed compiler and checksummed schema as a complete optional pair. Existing bundles remain accepted; partial, aliased or tampered pairs refuse. Existing channels require an explicit reviewed manager upgrade for the extended payload. Stable release packaging is unchanged.
Validation:
eac008e3, rebased ontonextatb1b281f9: 2,131 CLI tests, 68 skips, zero failures. DB tasks reused valid cache.792a6489fixes a Linux Cargo hardlink build guard and a retained-manager test fixture's bytecode pollution. The read-only Cargo input may have links; output/schema alias protections remain strict. Focused checks passed: 49 Bun tests, 37 Python installer tests, compiler rebuild, CLI typecheck and actionlint. Fresh exact-head CI is pending.792a6489, using private fixture version5.0.0-next.9999without publishing. An isolated archive install passed inventory/checksum/signature checks; the installed CLI compiled a symbolic fixture with no Bun/Rust on PATH. Repeated install preserved home identities; deselection refused launch; reselect restored the candidate. Native/CLI homes remained empty. This is packaging and software-selection evidence, not provider or application acceptance.New Linux/macOS compiler CI validates generation, shape parity and the real compiled CLI; both new compiler jobs pass on the current head. Execution of the new toolchain-container task and full native-format coverage remain subsequent gates. NC02 remains open for the full authored contract and NC03 remains responsible for execution integration. No published release or existing installed-runtime change is included.