Skip to content

fix(registry): restore Levenshtein edit costs - #20

Merged
samifouad merged 1 commit into
mainfrom
fix/levenshtein-19
Sep 12, 2026
Merged

samifouad merged 1 commit into
mainfrom
fix/levenshtein-19

Conversation

@samifouad

Copy link
Copy Markdown
Member

Restore the standard Levenshtein recurrence by charging one edit for each insertion and deletion. With --help, --version, and --verbose registered, --hep now suggests only --help.

Add a parser-level regression and distance cases covering empty strings, identity, substitutions, insertions/deletions, mixed edits, Unicode, and symmetry. Both new tests failed before the fix and pass afterward.

Closes #19.

Validation and consolidated QA/seam review: checked the recurrence and the Args::collect suggestion path; no findings. cargo test --locked and cargo clippy --locked --all-targets -- -D warnings both exit 0. Four existing external-fixture tests remain ignored. The changed file passes rustfmt and the diff passes whitespace checks; repository-wide formatting reports pre-existing import-order differences in two untouched files. No version bump or tag; this rides the next release.

Test output (dependency compilation omitted):

$ cargo test --locked
    Finished `test` profile [unoptimized + debuginfo] target(s) in 20.86s
     Running unittests src/lib.rs (target/debug/deps/deka_cli_core-d621367cd768945b)

running 42 tests
test registry::tests::non_legacy_commands_require_an_owner ... ok
test registry::tests::levenshtein_counts_each_edit ... ok
test registry::tests::inherit_only_works_and_tags_commands_legacy ... ok
test registry::tests::register_only_works ... ok
test registry::tests::inherit_and_register_collision_is_a_build_error ... ok
test token_file::tests::secret_token_debug_is_redacted ... ok
test registry::tests::parses_bare_allow_read_flag ... ok
test registry::tests::parses_deny_read_equals_path ... ok
test registry::tests::parses_allow_read_equals_list ... ok
test registry::tests::path_tokens_without_command_are_positionals ... ok
test registry::tests::owner_command_dispatches_its_handler ... ok
test registry::tests::misspelled_help_suggests_only_help ... ok
test registry::tests::unknown_flags_without_command_still_error ... ok
test token_file::tests::read_missing_token_returns_none ... ok
test update::trust::ceremony_floor_tests::real_generation_one_ceremony_anchor_is_accepted ... ignored, self-update is not yet built; needs the offline ceremony fixture at /etc/tana/harar-anchor, absent on CI runners
test token_file::tests::read_rejects_insecure_mode ... ok
test update::trust_anchor::tests::unknown_root_signer_does_not_help_meet_rotation_threshold ... ok
test whoami::tests::auth_origin_rejects_cleartext_and_url_metadata ... ok
test update::trust_anchor::tests::bootstrap_builder_emits_bytes_accepted_by_the_verifier ... ok
test update::trust::ceremony_floor_tests::differently_keyed_root_signed_generation_one_anchor_is_rejected ... ok
test whoami::tests::whoami_from_store_requires_token ... ok
test whoami::tests::whoami_rejects_redirect_without_forwarding_bearer ... ok
test whoami::tests::whoami_reports_rejection_without_token_material ... ok
test whoami::tests::whoami_resolves_principal_with_scopes ... ok
test token_file::tests::remove_is_idempotent ... ok
test token_file::tests::write_then_read_roundtrips_and_uses_0600 ... ok
test update::tests::unsigned_anchor_rotation_is_rejected_before_release_fetch ... ok
test whoami::tests::whoami_from_store_reads_shared_token_file ... ok
test update::tests::root_signed_revocation_rejects_a_still_valid_old_signature ... ok
test update::install::recovery_tests::pre_swap_recovery_keeps_current_and_never_restores_stale_prev ... ok
test update::tests::wrong_signature_is_rejected_and_never_installed ... ok
test update::tests::tampered_artifact_is_rejected_and_never_installed ... ok
test update::install::recovery_tests::post_swap_unhealthy_recovery_restores_only_transition_receipt_bytes ... ok
test update::tests::downgrade_is_rejected_before_artifact_fetch ... ok
test update::tests::monitor_authenticates_latest_without_fetching_or_installing_artifact ... ok
test update::tests::monitoring_a_new_major_does_not_approve_its_installation ... ok
test update::tests::failed_first_install_removes_candidate_from_executable_path ... ok
test update::tests::valid_release_installs_exact_fetched_bytes_once ... ok
test update::tests::root_signed_rotation_accepts_new_release_key_and_persists_generation ... ok
test update::tests::signed_update_quarantines_unreceipted_legacy_install_before_replacement ... ok
test update::tests::failed_health_check_atomically_restores_verified_previous ... ok
test update::tests::explicit_rollback_restores_verified_previous_without_network ... ok

test result: ok. 41 passed; 0 failed; 1 ignored; 0 measured; 0 filtered out; finished in 5.38s

     Running unittests src/bin/harar-anchor-init.rs (target/debug/deps/harar_anchor_init-2a7811b9ff642898)

running 0 tests

test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

     Running tests/context_bridge.rs (target/debug/deps/context_bridge-79da537133e49800)

running 1 test
test consumer_owned_state_maps_to_shared_dispatch_without_recapturing_cwd ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

     Running tests/context_env.rs (target/debug/deps/context_env-992d26865f5c8977)
context_env: 4 process-argv/cwd cases passed; command and subcommand dispatch passed
     Running tests/registry_bridge.rs (target/debug/deps/registry_bridge-76c0b7a17e42b9bc)

running 5 tests
test direct_mutable_registry_supports_existing_registration ... ok
test with_and_inherit_collide_in_either_order ... ok
test with_accepts_fn_once_preserves_owners_and_sees_prior_registrations ... ok
test with_does_not_relax_register_validation ... ok
test legacy_registration_parses_and_dispatches_commands_and_subcommands ... ok

test result: ok. 5 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

     Running tests/shared_cli.rs (target/debug/deps/shared_cli-daba652532cf8d19)

running 7 tests
test monitor_outcomes_use_the_stable_health_exit_code ... ok
test xdg_paths_have_one_shared_tana_namespace ... ok
test shared_auth_rejects_insecure_origin_before_storing_bearer ... ok
test device_login_rejects_redirect_response ... ok
test logout_keeps_local_token_when_server_revocation_fails ... ok
test login_validates_before_atomic_storage_and_logout_is_idempotent ... ok
test setup_is_resumable_idempotent_and_keeps_secrets_private ... ok

test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.29s

     Running tests/shared_cli_ruba_real_topology.rs (target/debug/deps/shared_cli_ruba_real_topology-616be7439f9f5657)

running 2 tests
test ruba_emission_rejects_redirects_without_following_them ... ok
test ruba_bearer_rejects_cleartext_non_loopback_origins ... ok

test result: ok. 2 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s

     Running tests/signed_release_real_topology.rs (target/debug/deps/signed_release_real_topology-7b862666800ed5d1)

running 3 tests
test client_verifies_real_linkhash_producer_across_process_boundary ... ignored, requires LINKHASH_REAL_BINARY built from the signed-release producer branch
test legacy_unreceipted_binary_migrates_only_to_real_signed_release ... ignored, requires LINKHASH_REAL_BINARY built from the signed-release producer branch
test real_linkhash_process_artifact_tamper_never_reaches_install_path ... ignored, requires LINKHASH_REAL_BINARY built from the signed-release producer branch

test result: ok. 0 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 0.00s

     Running tests/token_file_hardening.rs (target/debug/deps/token_file_hardening-11ea6476d74e659f)

running 6 tests
test token_core_does_not_put_secrets_on_subprocess_argv ... ok
test read_rejects_directory_token_paths ... ok
test read_rejects_world_readable_token_files ... ok
test read_rejects_malformed_token_files_without_leaking_secret ... ok
test write_replaces_world_readable_existing_token_with_private_file ... ok
test concurrent_writes_leave_a_complete_private_token_and_no_temp_files ... ok

test result: ok. 6 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.51s

   Doc-tests deka_cli_core

running 1 test
test src/update/verified.rs - update::verified::VerifiedArtifact (line 18) - compile fail ... ok

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.07s

Clippy output (dependency checks omitted):

$ cargo clippy --locked --all-targets -- -D warnings
    Checking deka-cli-core v0.4.2 (/Volumes/Projects/codex/cli-core-issue-19)
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 10.53s

-codex

@samifouad
samifouad merged commit 0ad715e into main Sep 12, 2026
4 checks passed
@samifouad
samifouad deleted the fix/levenshtein-19 branch September 12, 2026 05:17

This branch was successfully deployed

1 active deployment
public-ci — 5154c40e Deployed Sep 12, 2026 by samifouad via Build and test #21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

registry::levenshtein drops the +1 insertion/deletion cost — unrelated typo suggestions

1 participant