Skip to content

feat: validate native configuration with a bundled pure compiler - #154

Merged
roodboi merged 2 commits into
nextfrom
feat/native-config-compiler
Oct 7, 2026
Merged

roodboi merged 2 commits into
nextfrom
feat/native-config-compiler

Conversation

@roodboi

@roodboi roodboi commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Native configuration now has a standalone Rust owner and an explicit offline validation command: hack config validate --file <JSON> [--profile <names>] [--json]. It produces normalized symbolic plans and deterministic semantic hashes, or fixed redacted diagnostics with authored locations. The CLI checks the compiler protocol before sending input, bounds its I/O, strips inherited credentials, and reaps its child on timeout or interruption.

This foundation supports services/jobs, basic image/build selection, commands, source/storage mounts, environment directives, profiles, dependencies and readiness. Generated JSON Schema and TypeScript DTOs share the Rust types. Unsupported fields refuse. Runtime discovery, project migration, secret admission and backend execution are still outside this command; successful validation does not establish that a project can run.

Future native candidate bundles carry a signed compiler and checksummed schema as a complete optional pair. Existing bundles remain accepted; partial, aliased or tampered pairs refuse. Existing channels require an explicit reviewed manager upgrade for the extended payload. Stable release packaging is unchanged.

Validation:

  • Independent Rust and CLI transport reviews passed after their findings were fixed.
  • Rust formatting/Clippy and 19 tests pass; 47 shared shape cases pass through both Rust and an independent JSON Schema validator.
  • Relocated compiled CLI checks pass with no Rust/Bun on PATH: success, diagnostic forwarding/redaction, symbolic environment references, explicit-file selection, missing sidecar and no state writes.
  • Transport/CLI regressions cover version mismatch, output bounds, missing compiler, timeout, SIGINT/SIGTERM reaping, credential stripping and terminal escape handling.
  • Full Bun gates passed on eac008e3, rebased onto next at b1b281f9: 2,131 CLI tests, 68 skips, zero failures. DB tasks reused valid cache.
  • The follow-up at 792a6489 fixes a Linux Cargo hardlink build guard and a retained-manager test fixture's bytecode pollution. The read-only Cargo input may have links; output/schema alias protections remain strict. Focused checks passed: 49 Bun tests, 37 Python installer tests, compiler rebuild, CLI typecheck and actionlint. Fresh exact-head CI is pending.
  • The complete native candidate built at 792a6489, using private fixture version 5.0.0-next.9999 without publishing. An isolated archive install passed inventory/checksum/signature checks; the installed CLI compiled a symbolic fixture with no Bun/Rust on PATH. Repeated install preserved home identities; deselection refused launch; reselect restored the candidate. Native/CLI homes remained empty. This is packaging and software-selection evidence, not provider or application acceptance.
  • Bounded M3 invocation measurements (three warmups, 30 repetitions, 133-byte offline fixture): direct Rust median 1.8 ms, protocol-checked transport 3.7 ms, full compiled CLI 103 ms. These measure invocation cost only; they do not establish app startup or resource gains.

New Linux/macOS compiler CI validates generation, shape parity and the real compiled CLI; both new compiler jobs pass on the current head. Execution of the new toolchain-container task and full native-format coverage remain subsequent gates. NC02 remains open for the full authored contract and NC03 remains responsible for execution integration. No published release or existing installed-runtime change is included.

@roodboi
roodboi marked this pull request as ready for review October 7, 2026 03:22
@roodboi
roodboi merged commit 4c63898 into next Oct 7, 2026
11 checks passed
@roodboi
roodboi deleted the feat/native-config-compiler branch October 7, 2026 03:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant