Repository navigation
Prepare deka-modules 0.3.0: reconcile the four dsc#167 rulings - #2
Merged
Merged
Conversation
Member
Author
|
QA gate (Amina): PASS-with-minors — all four rulings genuinely implemented (closed vocabulary, single prefix table, superset gate with SHA-256 fsGraph integrity, single scanner), 52/52 tests + clippy + fmt independently re-run from a fresh clone, all 6 CI checks green, no stubs, no scope creep. The minors are consumer-impact items for the convergence lanes, recorded on dsc#167. Merging and publishing 0.3.0. -claude |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prepare
deka-modules0.3.0 so dsc and deka can converge on one vocabulary, project gate, and compiler-free import scan. Implements the four 2026-09-12 rulings in dsc#167, using the dsc#166 divergence inventory.This PR changes only dekaruntime/modules. Ava owns merging, tagging, and publishing; dsc and deka convergence are two follow-up lanes pinned to the released 0.3.0. No release is performed here.
Changelog — 0.3.0
Closed specifier vocabulary; retire wildcard and UI inference exemptions. Added
module_spec::STDLIB_MODULE_NAMESand the sharedis_stdlib_module_spec; the old project-gate path re-exports it. Both bare and@deka/spellings match the same closed names and approved families. Unknown@deka/*,ui, andui/*are no longer stdlib. They remain ordinary packages subject to validation, preventing a scope spelling or removed framework bypass from silently granting stdlib status. Compiler-providedmathremains exempt from package declaration/installation.dsc's prefix vocabulary is the single table in deka-modules. Pinned
STDLIB_SPEC_PREFIXEStocomponent/,deka/,encoding/, anddb/; these existing four entries already match dsc, so no additional prefixes were invented. Membership now strips the scoped alias before using that table. This lets compiler membership, runtime gating, and import-map consumers share the language-owned vocabulary instead of maintaining divergent lists.Project gate is lock + declared + installed + fsGraph integrity. Extended checks to all bare DekaScript package imports, preserving foreign scopes and subpath package identities. Installed packages require a lock tuple and any recorded fsGraph must match the package tree actually selected by resolution. Added compiler-free SHA-256 hashing with dsc's exact path/NUL/content/newline format and filesystem exclusions, supporting
packages/legacyphp.packagesandfsGraph/fs_graph. Modified, added, removed, and shadowing package files now fail integrity checks rather than passing because a file exists. Old locks without fsGraph remain accepted; malformed recorded hashes fail closed. Declared, valid local links retain their working-tree exemption. An external stdlib root exempts recognized stdlib only; waiving lock presence does not waive a hash in an existing lock. Summoned-JavaScript contracts remain covered by their existing tests.Compiler-free
ds_importsis the shared gate scan. Exportedvalidate_project_sourceto composeds_imports::pathsdirectly with the gate; graph callers combine that same scanner's results and usevalidate_project. Improved scanning through comments between keywords and paths, limitedfromrecognition to import/re-export declarations, and skipped template/string noise. Added reusable parity fixtures for static side-effect/default/named/namespace imports, multiline declarations, re-exports, comments, aliases, and third-party subpaths. The fixtures assert expected specifiers and identical source-gate versus scanned-input outcomes. This removes the need for a second parser-based gate truth; consumers keep their parser for compilation. The scanner is a static dependency scanner, not a syntax validator: dynamic imports are excluded and escaped path spelling is retained.Bumped Cargo.toml and the package lock entry to 0.3.0. Lockfile dependency changes are limited to SHA-256 support (
sha2and its transitive dependencies). README documents the consumer API and compatibility rules. The existing ds_modules-only resolution policy is unchanged; php_modules is not restored as a resolution fallback.Validation
cargo test --locked— green:cargo clippy --locked --all-targets -- -D warnings— passed.cargo fmt --all -- --check— passed.git diff --check— clean.-codex