Skip to content

Prepare deka-modules 0.3.0: reconcile the four dsc#167 rulings - #2

Merged
samifouad merged 1 commit into
mainfrom
feat/reconcile-167
Sep 12, 2026
Merged

samifouad merged 1 commit into
mainfrom
feat/reconcile-167

Conversation

@samifouad

Copy link
Copy Markdown
Member

Summary

Prepare deka-modules 0.3.0 so dsc and deka can converge on one vocabulary, project gate, and compiler-free import scan. Implements the four 2026-09-12 rulings in dsc#167, using the dsc#166 divergence inventory.

This PR changes only dekaruntime/modules. Ava owns merging, tagging, and publishing; dsc and deka convergence are two follow-up lanes pinned to the released 0.3.0. No release is performed here.

Changelog — 0.3.0

  1. Closed specifier vocabulary; retire wildcard and UI inference exemptions. Added module_spec::STDLIB_MODULE_NAMES and the shared is_stdlib_module_spec; the old project-gate path re-exports it. Both bare and @deka/ spellings match the same closed names and approved families. Unknown @deka/*, ui, and ui/* are no longer stdlib. They remain ordinary packages subject to validation, preventing a scope spelling or removed framework bypass from silently granting stdlib status. Compiler-provided math remains exempt from package declaration/installation.

  2. dsc's prefix vocabulary is the single table in deka-modules. Pinned STDLIB_SPEC_PREFIXES to component/, deka/, encoding/, and db/; these existing four entries already match dsc, so no additional prefixes were invented. Membership now strips the scoped alias before using that table. This lets compiler membership, runtime gating, and import-map consumers share the language-owned vocabulary instead of maintaining divergent lists.

  3. Project gate is lock + declared + installed + fsGraph integrity. Extended checks to all bare DekaScript package imports, preserving foreign scopes and subpath package identities. Installed packages require a lock tuple and any recorded fsGraph must match the package tree actually selected by resolution. Added compiler-free SHA-256 hashing with dsc's exact path/NUL/content/newline format and filesystem exclusions, supporting packages/legacy php.packages and fsGraph/fs_graph. Modified, added, removed, and shadowing package files now fail integrity checks rather than passing because a file exists. Old locks without fsGraph remain accepted; malformed recorded hashes fail closed. Declared, valid local links retain their working-tree exemption. An external stdlib root exempts recognized stdlib only; waiving lock presence does not waive a hash in an existing lock. Summoned-JavaScript contracts remain covered by their existing tests.

  4. Compiler-free ds_imports is the shared gate scan. Exported validate_project_source to compose ds_imports::paths directly with the gate; graph callers combine that same scanner's results and use validate_project. Improved scanning through comments between keywords and paths, limited from recognition to import/re-export declarations, and skipped template/string noise. Added reusable parity fixtures for static side-effect/default/named/namespace imports, multiline declarations, re-exports, comments, aliases, and third-party subpaths. The fixtures assert expected specifiers and identical source-gate versus scanned-input outcomes. This removes the need for a second parser-based gate truth; consumers keep their parser for compilation. The scanner is a static dependency scanner, not a syntax validator: dynamic imports are excluded and escaped path spelling is retained.

Bumped Cargo.toml and the package lock entry to 0.3.0. Lockfile dependency changes are limited to SHA-256 support (sha2 and its transitive dependencies). README documents the consumer API and compatibility rules. The existing ds_modules-only resolution policy is unchanged; php_modules is not restored as a resolution fallback.

Validation

cargo test --locked — green:

Unit tests:        42 passed; 0 failed; 0 ignored
Integration tests: 10 passed; 0 failed; 0 ignored
Doc tests:          0 passed; 0 failed
Total:             52 passed; 0 failed
  • cargo clippy --locked --all-targets -- -D warnings — passed.
  • cargo fmt --all -- --check — passed.
  • git diff --check — clean.
  • Regression coverage includes closed names/prefixes, wildcard/UI rejection, fsGraph byte-format parity and exclusions, add/change/delete mismatches, missing lock entries, malformed hashes, legacy metadata, scoped third-party subpaths, local-link declaration/staleness, selected-alias integrity, and scanner fixtures.
  • Consumer integration is intentionally deferred to the two lanes after publication; no claim of a dsc/deka end-to-end test in this PR.

-codex

@samifouad

Copy link
Copy Markdown
Member Author

QA gate (Amina): PASS-with-minors — all four rulings genuinely implemented (closed vocabulary, single prefix table, superset gate with SHA-256 fsGraph integrity, single scanner), 52/52 tests + clippy + fmt independently re-run from a fresh clone, all 6 CI checks green, no stubs, no scope creep. The minors are consumer-impact items for the convergence lanes, recorded on dsc#167. Merging and publishing 0.3.0.

-claude

@samifouad
samifouad merged commit 74fb67c into main Sep 12, 2026
6 checks passed
@samifouad
samifouad deleted the feat/reconcile-167 branch September 12, 2026 20:52

This branch was successfully deployed

1 active deployment
public-ci — 5bd2edd1 Deployed Sep 12, 2026 by samifouad via fmt, clippy, and test #2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant