Skip to content

Releases: WilliamSmithEdward/ROneCOne

ROneCOne 1.10.3

Choose a tag to compare

@WilliamSmithEdward WilliamSmithEdward released this 29 Sep 18:31

ROneCOne 1.10.3

This patch adds ClamAV and YARA-X checks to Security CI. The runtime API and behavior are
unchanged. The shipped VBA modules carry the 1.10.3 release header.

ClamAV checks the runtime and all 16 demo workbooks with its official signatures. YARA-X scans
those files and the workbooks' unpacked members using the pinned, checksum-verified YARA Forge
Core rules. Scanner failures fail CI. The previous demo workbooks had one reviewed false positive
from ordinary Office/VBA references; the 1.10.3 packaging removed that match, so the exception
list is empty. Any new detection requires review.

Validation

The Security and CI workflows passed for the security-scan change before release packaging.
After stamping and repackaging the 16 workbooks, 99 Python tests passed. pyVBAanalysis reported
zero diagnostics on the complete source project and standalone runtime. olevba and mraptor matched
the reviewed baseline. YARA-X found no matches in the runtime, workbooks, or unpacked workbook
members. ClamAV 1.5.4 scanned the final files with 3,628,083 signatures and found no infections.
Every packaged VBA module round-tripped byte-for-byte through pyOpenVBA. The live Excel,
benchmark, and visual release gates were skipped for this CI-only patch.

Full changelog

ROneCOne 1.10.2

Choose a tag to compare

@WilliamSmithEdward WilliamSmithEdward released this 29 Sep 05:15

ROneCOne 1.10.2

This release adds a security policy and scans every change, and every release, with olevba and
mraptor. The runtime renames one private constant that both tools read as code that runs on its
own. Behavior and the public surface are unchanged, so upgrading is a drop-in replacement.

Added

SECURITY.md explains how to report a vulnerability privately, from the repository's Security
tab, and what the runtime can reach: the network through HttpClient and Xml.Load, commands
through Process, the files and databases your code names, and Windows APIs in four libraries,
each only when your code calls it. The README gains CI and Security badges and a Security section.

A Security workflow scans ROneCOne.cls and every demo workbook with olevba and MacroRaptor
(mraptor) on every push and pull request, and holds each file's results to a reviewed baseline.
It fails on a finding that appears or disappears, on changed mraptor flags, on code that runs on
its own, and on P-code that its source does not explain. mraptor rates every file Macro OK, with
flags -WX: the runtime writes files and memory and runs COM objects, commands, and Windows APIs
by design, and nothing in it runs on its own.

Each release from this one on carries a security report beside its SHA-256 manifest, here
v1.10.2-security-report.md. A workflow writes it from the published assets: each file's hash,
olevba findings, and mraptor verdict, and how they compare with the baseline at the release tag.

Changed

The runtime's private constant for a file watcher's change record is ROLE_FILE_EVENT rather
than ROLE_FILE_CHANGE. olevba and mraptor treat any name ending in _Change as an ActiveX
event handler, so they reported the runtime and every demo workbook as code that runs when the
file opens. None of them does.

Fixed

The demo worksheets' code cells hold only VBA. Three cells mixed English into the code, and the
Exceptions clean-import row wrote a fixed string where it now checks the trace for a skipped row.
Rows on the Files, Process, Query, Collections, and Zip sheets now show the calls the demo makes,
among them ReadAllText(helloPath) for the Files text row and a single sort for the Process
standard-input row. Start Here and Benchmarks titles say "and" where they said "+", the Excel
Table demo names its feature "Excel Tables", and benchmark counts show thousands separators.

The Zip demo's benchmark inflates a 50,000-line file rather than a 1,000-line one. VBA's Timer
returns a Single, which moves in 1/128-second steps after 18:12, and the smaller file inflated
inside one step often enough that about one evening run in three measured zero seconds and the
demo runner failed it. The benchmark now takes about 0.09 seconds against its 5-second gate.

Development

CI runs the newest pyVBAanalysis release, and the local pin moves from 2.2.0 to 2.3.1. That
release stops reporting the runtime's Item property, a Variant Property Get beside an Object
Property Set that Excel compiles. Its new --whole-project flag analyzes ROneCOne.cls alone,
as the complete project a user imports. In the combined run over the runtime, tests, and demos,
a call from the runtime into a test or demo module would resolve.

The live suite's hash-set read scenario makes 100,000 reads, ten passes over its 10,000 items.
One pass took about one Timer step in the evening, so it could have read zero.

Release evidence

Each of three fresh Microsoft 365 Excel processes passed all 1005 live assertions, and all ten
suite benchmark scenarios met their release gates in every sample. The medians ran invocation
0.11, collection 0.16, ordering 0.92, dictionary build and read 0.13, 100,000 indexed lookups
0.28, keyed mutation 0.66, 10,000 list writes 0.06, 2,000 row reads 0.06, 100,000 hash set reads
0.10, and constrained maintenance 0.50 seconds.

The Zip workbook was rebuilt from its builder. All sixteen were repackaged with the stamped
modules and run in place, and all 205 of their examples passed. An AutoFit check in Excel over
every cell reported what it reported for 1.10.1: only the two Text digests, which wrap inside rows
sized to hold them. Every rendered sheet was reviewed. The VBE casing round trip over the runtime,
all eighteen demo modules, and a host module brought every token back as written.

Static analysis on pyVBAanalysis 2.3.1 reported zero diagnostics across the runtime source, the
runtime on its own, the live test modules, the demo modules, and all sixteen final workbooks, with
inline suppressions disabled. olevba and mraptor found exactly the reviewed baseline in the
runtime and every workbook. 96 Python contract tests pass. Every packaged VBA module
round-tripped byte-for-byte, and after Excel saved each workbook, its modules still match their
sources apart from the VBE joining 27 continued Attribute lines in the runtime.

Full changelog

ROneCOne 1.10.1

Choose a tag to compare

@WilliamSmithEdward WilliamSmithEdward released this 23 Sep 23:50

ROneCOne 1.10.1

ROneCOne.cls no longer declares variables that nothing reads. Behavior and the public surface
are unchanged, so upgrading is a drop-in replacement and no calling code changes.

Changed

pyVBAanalysis 2.2.0 added checks for unused variables and constants and for variables that are
assigned but never read. Run over 1.10.0, they reported 57 declarations across the runtime, the
live tests, and the demo modules. None was a constant, and removing them changes no behavior.

In the runtime, two linked-list node fields had gone unused since 1.0.0, because a node finds its
neighbors by index through the list that owns it. Four locals were never referenced, and the HTTP
poll saved an error source it never raised. Eight calls stored a result in a throwaway variable
only to discard it, and they are now plain statements. CsvClassifyNumber returns the type of
its overflow probe rather than restating it as a constant, which is the same answer.

The Collections, Data, HTTP, and Tasks demos drop the same throwaway variables, and the Data and
Tasks worksheets show the plain calls. The Collections, Data, and Excel Table demos also no longer
declare locals such as Dim Age As Variant for the names they reach through bang syntax. Earlier
pyVBAanalysis versions reported !Age as undeclared without them.

Development

The repository's static-analysis gate moved to pyVBAanalysis 2.2.0 and pyOpenVBA 6.0.0, so a
variable that nothing reads now fails it. VBA has no discard syntax. A Function called only for
its effect is written as a statement, and where VBA requires an assignment, as with a property
read, a conversion probe, or a delegate(args) call, the code reads the value back. Eight live
assertions came from that: six check that an Action returns Empty and that a failed invocation
returns nothing, and two check that a refused count returns none.

Release evidence

Each of three fresh Microsoft 365 Excel processes passed 1005 live assertions, the 997 of 1.10.0
plus the eight above. All ten suite benchmark scenarios met their release gates in every sample.
The medians ran invocation 0.11, collection 0.17, ordering 0.94, dictionary build and read 0.14,
100,000 indexed lookups 0.26, keyed mutation 0.66, 10,000 list writes 0.07, 2,000 row reads 0.06,
10,000 hash set reads 0.01, and constrained maintenance 0.50 seconds.

The Tasks and Data workbooks were rebuilt from their builder. All sixteen were repackaged with the
stamped modules and run in place, and all 205 of their examples passed. An AutoFit check in Excel
over every cell reported what it reported for 1.10.0: only the two Text digests, which wrap
inside rows sized to hold them. Every rendered sheet was reviewed. The VBE casing round trip over
the runtime, all eighteen demo modules, and a host module brought every token back as written.

Static analysis on pyVBAanalysis 2.2.0 reported zero diagnostics across the runtime source, the
live test modules, the demo modules, and all sixteen final workbooks, with and without inline
suppressions. 89 Python contract tests pin the source, the demos, and the documentation. Every
packaged VBA module round-tripped byte-for-byte.

Full changelog

ROneCOne 1.10.0

Choose a tag to compare

@WilliamSmithEdward WilliamSmithEdward released this 23 Sep 02:54

ROneCOne 1.10.0

The sixteen demo workbooks now fit their text in Excel. ROneCOne.cls differs from 1.9.1 only
in its release header, so upgrading is a drop-in replacement and no calling code changes.

Fixed

The renders used to review the demos come from a tool that draws Calibri and Consolas narrower
than Excel does, so they hid most of the layout problems. Measured with Excel's own AutoFit, the
1.9.1 workbooks split or clipped 74 cells, soft-wrapped 50 code lines mid-expression, and cut off
text in rows too short to hold it. Excel keeps the height a row was saved with and does not
resize it on open, so a row the builder left unsized showed only the first line of its wrapped
text. Every capability demo's title band was also a few points short of its 24-point title.

The builders now size everything from Excel's measurements. A code line longer than its column
breaks with a VBA line continuation, the style the Excel Table demo already used, and each example
row takes its height from its longest cell. Five snippets that already carried a statement onto a
second line lacked the _ continuation VBA requires, and now end the line with it. Every table
row has an explicit height. Value columns widen only in the DateTime, HTTP, and Excel Table demos,
where a timestamp, an escaped string, or a joined list needs the room. The two SHA-256 digests on
the Text sheet are 64 hex characters with nowhere to break, so they still wrap mid-string, inside
rows sized to hold them.

Expected Booleans showed as checkboxes beside the plain TRUE the macro writes, because the
workbook builders stored a JavaScript Boolean as an Excel checkbox cell. They are now written as
=TRUE and =FALSE, so both columns show TRUE.

The capability demos' Examples titles read naturally: "Live HTTP examples" rather than "Live
http + async examples". Their Status columns show PASS in green and CHECK in red, as the
Delegates and Collections demos already did, and NOT RUN now shows in amber in all sixteen.

The HTTP benchmark times the same three downloads overlapped and in sequence, and the sheet now
labels both columns and shows both to six decimals. Its note says what overlapping can save and
that fast responses can take the same time either way. The demo module's comments no longer
promise a saving the measurement does not always show. The Collections benchmark subtitle names
both scales it measures.

Changed

The Excel Table demo serializes its sample row with ToJson(True), so the JSON shows indented and
wraps at its own line breaks rather than splitting inside a key.

Release evidence

Each of three fresh Microsoft 365 Excel processes passed the same 997 live assertions as 1.9.1.
All ten suite benchmark scenarios met their release gates in every sample. The medians ran
invocation 0.11, collection 0.16, ordering 0.93, dictionary build and read 0.14, 100,000 indexed
lookups 0.26, keyed mutation 0.66, 10,000 list writes 0.06, 2,000 row reads 0.07, 10,000 hash set
reads 0.01, and constrained maintenance 0.47 seconds.

All sixteen demo workbooks were rebuilt from their builders and run in place, and all 205 of their
examples passed. An AutoFit check in Excel over every cell, merged title bands included, reported
only the two digests, and every rendered sheet was reviewed. The VBE casing round trip over the
runtime, all eighteen demo modules, and a host module brought every token back as written.

Static analysis on pyVBAanalysis 1.3.1 reported zero diagnostics across the runtime source, the
live test modules, the demo modules, and all sixteen final workbooks. 89 Python contract tests pin
the source, the demos, and the documentation. Every packaged VBA module round-tripped
byte-for-byte.

Full changelog

ROneCOne 1.9.1

Choose a tag to compare

@WilliamSmithEdward WilliamSmithEdward released this 23 Sep 00:42

ROneCOne 1.9.1

Importing ROneCOne.cls no longer rewrites the spelling of names in the rest of the project
(issue #6), and every module that ships
now opens with its release and the MIT license.

Upgrading needs no change to calling code. No member was added or removed, and every public
parameter keeps its name and position. 324 of them changed case, as value became Value in
Add, and VBA matches named arguments regardless of case. 75 parameters on 63 Friend members
were renamed. Those are the runtime's internal wiring, absent from the reference, so only code
calling them by named argument would notice.

A project that ran an earlier release can keep some names in the spelling the old class gave them.
Getting started covers
replacing the class and has a procedure to paste and delete that restores them.

Fixed

VBA keeps one spelling per identifier across a project, and a declaration anywhere sets it. The
runtime declared more than a thousand parameters and locals in lowercase whose names Excel,
Office, or VBA spell otherwise. Imported into a project, it turned .Value into .value and
.Text into .text in every module, and each export carried the change as diff noise. Exported
through the VBE beside a host module that declares none of those names, 24 names in the host came
back recased, Count, Item, Rows, and Value among them. The runtime recased its own members
too, and ROneCOne and ModernJsonInVBA recased each other when they shared a project.

Public parameters now take the spelling the type libraries use, as Excel's own parameters do.
Parameters of Private and Friend members, locals, UDT fields, and Declare parameters were renamed
to names no reference defines, such as value to itemValue and index to idx. Guid and
Xml keep their .NET spelling, so a host that writes GUID or .XML still sees those two
recased.

The demo modules had the same defect inside their workbooks, where Dim json As String turned
ROneCOne.Json into ROneCOne.json. So did the documentation's examples, which readers copy into
their own modules. Both now use names that no reference and no ROneCOne member defines. The
ModernJsonInVBA side of the collision is tracked in
ModernJsonInVBA#1.

Changed

Every module that ships opens with the release it belongs to and the full MIT license, directly
below Option Explicit: the runtime and each module packaged into the demo workbooks. A demo
module copied out of its workbook used to carry neither, and the runtime's license sat on line
208, below the Windows declarations. tools/stamp_release_headers.py writes the header from the
newest dated changelog heading and from LICENSE.

Guards added

tests/python/test_casing.py holds the runtime, the demo modules, and every documentation example
to one spelling per name and to the spelling the default references use.
tools/run_casing_roundtrip.ps1 exports a host project through the VBE and requires every token
back as written. A source contract fails while any shipped module's header disagrees with the
changelog or LICENSE.

Release evidence

Each of three fresh Microsoft 365 Excel processes passed the same 997 live assertions as 1.9.0.
All ten suite benchmark scenarios met their release gates in every sample. The medians ran
invocation 0.11, collection 0.18, ordering 0.95, dictionary build and read 0.16, 100,000 indexed
lookups 0.30, keyed mutation 0.70, 10,000 list writes 0.07, 2,000 row reads 0.07, 10,000 hash set
reads 0.01, and constrained maintenance 0.48 seconds.

All sixteen demo workbooks were repackaged with the stamped modules and run in place, and all 205
of their examples passed. The VBE casing round trip over the runtime, all eighteen demo modules,
and a host module brought every token back as written.

Static analysis on pyVBAanalysis 1.3.1 reported zero diagnostics across the runtime source, the
live test modules, the demo modules, and all sixteen final workbooks. 89 Python contract tests pin
the source, the demos, and the documentation. Every packaged VBA module round-tripped
byte-for-byte.

Method note

The upgrade path was measured before the guide was written. A workbook holding 1.9.0 and two host
modules was saved with the host names recased, then upgraded by removing the class and importing
this one through the VBE. Names this runtime declares came back, 17 of the 24 in the first host
module. The rest did not. A second host module references all 72 names that some release declared
and 1.9.1 does not; 64 of them kept the old spelling, and the imported runtime took five of them
itself. Saving and reopening between removing the old class and importing the new one still left
59. Pasting the guide's procedure and deleting it restored every name in all three modules, and
the spellings survived saving and reopening.

A comparison of the public surface against 1.9.0 also ran before release. It found one parameter
renamed rather than recased, TryUpdate's newValue, which would have broken a named-argument
caller. The parameter was restored, and every public name now matches 1.9.0.

Full changelog

ROneCOne 1.9.0

Choose a tag to compare

@WilliamSmithEdward WilliamSmithEdward released this 02 Aug 20:16

ROneCOne 1.9.0

Excel Tables become a first-class input, and the JSON writer stops polluting the caller's error
state.

The two are connected. Building a demo for Tables turned up the second defect, and reviewing that
demo turned up the honest answer to the first: the runtime had never heard of a ListObject.
Searching the source for the type returned zero hits, the documentation never mentioned it, and
the only advice on offer was to pass listObject.Range yourself and work around a 438.

Upgrading is a drop-in replacement of ROneCOne.cls. One behavior changes, in favour of the
documented contract: Json.Serialize handed a bare Range used to serialize that cell's value
and now raises, which is what the JSON reference has always said it would do.

Added

Every worksheet entry point takes a Table. DataTableFromRange, ListFromRange,
LoadFromRange, and ToRange accept a ListObject or a single ListColumn directly, resolved
through one guarded helper. With headers wanted the slice stops after the last body row, so a
totals row is never read as data, and an empty Table yields its columns with no rows rather than
failing.

ROneCOne.Table(listObject) goes further: the table it returns remembers where it came from.
Refresh re-reads it in place, and WriteBack writes rows into the Table and resizes it to fit.
ToRange given a Table performs the same write, so a DataView can drive it.

Refresh is a Sub rather than a Function returning a copy, because a bare Refresh statement
on a Function would compile and silently do nothing.

Excel behavior this works around

Four things about resizing a Table are awkward, and every one was measured in a live instance
before a line of the implementation existed:

  • Resizing to a header row alone raises 1004: a Table must keep at least one data row. Writing
    zero rows goes through DataBodyRange.Delete instead, which leaves the Table and its headers
    in place.
  • Shrinking leaves the vacated cells populated below the Table. WriteBack clears them.
  • A totals row lands inside the requested range when a Table grows and outside it when one
    shrinks. Rather than encode that asymmetry, totals are switched off around the resize and
    restored after.
  • Name, style, and header text survive a resize, so none of them need saving.

Fixed

Every JSON serialization left a stray error behind
(issue #5). This is the IsArray
hazard closed in 1.8.1, in a second intrinsic. VarType also evaluates its argument in a value
context, so a Variant holding a runtime value was dereferenced through its default member, Run,
which rejects the zero arguments that dereference supplies. VarType then reported vbObject
precisely because that call failed, so the text came out correct and only the error state was
poisoned, for any caller running under On Error Resume Next. The JSON writer opens with a
VarType test on the value it was handed, so lists, dictionaries, tables, rows, and views were
all affected. ToCsv was not, because the CSV writer never asks a Variant for its type.

All 52 type tests now route through a guarded VarTypeOf, and a source contract pins VarType to
that one site.

ToJson(True) also ignored indentation for tables, rows, and views, returning text identical to
ToJson() while the documentation promised otherwise. The indented writer now covers them.

A note on the guard that caught its own author

The source contract that pins Friend member access found a regression inside this very change.
Collection.Item returns a Variant, so reading the Friend InternalDataRows off it in the
new write-back path reintroduced the 438 closed in
issue #3 with no Object local
anywhere in the code. The contract as written only looked at declared late-bound locals, so the
analyzer caught it and the contract did not. The contract now rejects any .Item(...).Member
chain reaching a Friend member.

Release evidence

Each of three fresh Microsoft 365 Excel processes passed 997 live assertions, up from 959 by
thirty-eight: twelve covering error cleanliness and indented output across every serializable
shape, and twenty-six over a real ListObject built in the suite workbook, covering each bridge
taking the Table directly, the attached surface, WriteBack shrinking with the vacated cells
cleared, Refresh, WriteBack growing, a view driving ToRange into the Table, a totals row
surviving the resize, and four guardrails asserted on the raised error rather than the answer.

All ten suite benchmark scenarios met their release gates in every sample. Sixteen demo workbooks
were rebuilt against this runtime and every example in each one passed; the Excel Table demo's
forty-four examples ran with its 5,000-row read, filter, and write-back benchmark inside its
five-second gate.

Static analysis on pyVBAanalysis 1.3.0 reported zero diagnostics across the runtime source, the
live test modules, and all sixteen demo modules. Python contract tests pin the source and demo shapes. Every packaged VBA
module round-tripped byte-for-byte.

Method note

Both defects were reproduced live before any code changed, and neither is visible to static
analysis. The VarType defect was isolated by testing each construct against a Variant holding a
runtime value and recording Err after each one: argument passing is innocent in every form, and
VarType alone fires the default member. That the intrinsic dereferences a foreign object through
its default member was then confirmed directly, with a Range holding text reporting vbString
rather than vbObject.

Full changelog

ROneCOne 1.8.1

Choose a tag to compare

@WilliamSmithEdward WilliamSmithEdward released this 02 Aug 04:14

ROneCOne 1.8.1

A patch release for two defects in the same family: VBA quietly dereferencing a runtime value
through its default member, or refusing to reach a Friend member at all, when a value travels as
an Object or a Variant. Both were reported with reproductions, both were confirmed live
before any code changed, and both are now guarded by source contracts so the class of defect
cannot return rather than only the reported site.

No public surface changed. Upgrading is a drop-in replacement of ROneCOne.cls.

Fixed

  • OneOf given a single ROneCOne sequence raised run-time error 438 instead of building the
    membership condition (issue #3).
    IsSequenceContainer read the Friend InternalRole through an Object local, and VBA keeps
    Friend members off the IDispatch interface, so the read compiled clean and failed only when
    executed, even though the caller is the class that owns the member. Binding through a typed
    local fixes it. Every previous OneOf test passed an array or two scalars, so nothing reached
    the branch, which is how it survived.
  • IsArray left a stray error behind when handed a Variant holding a runtime value
    (issue #4). IsArray evaluates its
    argument in a value context, so VBA dereferenced the object through its default member, Run,
    which rejects the zero arguments that dereference supplies. The raise was swallowed wherever a
    caller had On Error Resume Next active, which propagates into callees with no handler of their
    own, so calls returned correct answers while leaving Err dirty for the caller to trip over
    somewhere unrelated. Two further call sites were exposed to the same hazard, in
    DeserializeOnly and in primary-key argument building.

Guards added

Both fixes are enforced structurally rather than by the single repaired line. A source contract
sweeps every procedure for a Friend member read through an Object or Variant local, joining
line continuations and cross-referencing all 270 Friend members; it found exactly one occurrence,
the reported one. A second contract asserts that IsArray appears exactly once in the runtime,
inside a guarded IsArrayValue helper that tests IsObject first, since an object is never an
array.

Release evidence

Each of three fresh Microsoft 365 Excel processes passed 959 live assertions, up from 955 by four
new cases covering OneOf with a sequence, a single-match sequence, and the bare Where()
receiver that exposed the second defect. That last case asserts the error state rather than only
the answer, because a correct answer was exactly what hid the bug. All ten suite benchmark
scenarios met their release gates in every sample; the medians ran invocation 0.11, collection
0.16, ordering 0.90, SHA-256 at 10,000 and 100,000 elements 0.13 and 0.23, keyed mutation 0.63,
and constrained maintenance 0.45 seconds.

Static analysis reported zero diagnostics across the runtime source, the live test modules, and
all fifteen demo modules; 79 Python contract tests pin the source and demo shapes. Every packaged
VBA module round-tripped byte-for-byte.

Method note

Neither report was taken on faith. Each was reproduced against the current runtime in a headless
instance before a line changed, and the second was localized by tracing Err through a throwaway
instrumented copy of the class, which showed the error appearing between two adjacent statements
and identified IsArray as the value context responsible. Static analysis passes both defects
cleanly, so only a live run could have found either.

Full changelog

ROneCOne 1.8.0

Choose a tag to compare

@WilliamSmithEdward WilliamSmithEdward released this 28 Jul 03:21

ROneCOne 1.8.0

ROneCOne 1.8.0 is about doing less work. A query now runs where the data lives instead of after
loading every row into Excel. A command can be held in conversation instead of restarted for each
line. And a large JSON response can be read for the handful of members you actually want, rather
than parsed in full and then discarded. Each one replaces a pattern that looked fine until the
data grew.

Highlights

  • connection.Queryable(tableName) compiles the runtime's own expression trees into parameterized
    SQL, so the filter happens in the database. Where, OrderBy, OrderByDescending, ThenBy,
    ThenByDescending, SelectColumns, Take, and Skip compose immutably; Count, AnyItem,
    FirstOrDefault, ToDataTable, ToDataTableAsync, and CountAsync execute; ToSqlString and
    SqlParameterValues render exactly what will be sent. Every captured constant leaves as a ?
    marker, so a value can never be read as SQL. A Null becomes IS NULL, string helpers become
    dialect-escaped LIKE, and IsIn becomes an IN list. Anything untranslatable refuses with the
    typed ROneCOne.QueryError instead of quietly falling back to a client-side scan
  • ROneCOne.Process.StartSession(command, [workingDirectory], [encodingName]) keeps one cmd.exe
    alive for a real conversation: WriteAsync and WriteLineAsync queue input, CloseInput
    signals end of file, ReadLineAsync and ReadErrorLineAsync await the next line on each stream
    separately, ReadAvailable and ReadErrorAvailable take what is buffered, ReadToEndAsync
    collects the rest, and WaitForExitAsync resolves to the exit code, alongside HasExited,
    ExitCode, ProcessId, and KillProcess. Nothing blocks Excel: reads size themselves from
    PeekNamedPipe, and writes ride an overlapped named pipe so an oversized payload pends instead
    of freezing the host
  • Json.DeserializeOnly(text, paths) walks a document once and materializes only the paths you
    name, preserving structure so navigation is identical to Deserialize, and
    Json.DeserializeAt(text, path) returns the single value one path addresses. DeserializeTable
    and DeserializeObjects now apply arrayPath during the scan rather than after a full parse
  • Binding is also fixed rather than merely faster: DeserializeInto and DeserializeObjects no
    longer raise on a JSON member the target class does not model, matching System.Text.Json
  • A fifteenth demo workbook queries a generated workbook offline through the ACE provider, and the
    process and JSON demos gain sessions and partial reads in situ

Release evidence

Each of three fresh Microsoft 365 Excel processes passed 955 live assertions, including SQL text
and bound values across both dialects, an injection-shaped customer name that matches one row
literally and cannot widen the result set, IS NULL translation, dialect-escaped wildcards, every
query refusal path, a two-answer conversation with one process, separated standard error, sort
finishing only once CloseInput signals end of file, KillProcess, and a partial JSON read that
is required to beat a whole parse on a document whose bulk is one unwanted member. All ten suite
benchmark scenarios met their release gates in every sample; the medians ran invocation 0.10,
collection 0.16, ordering 0.90, SHA-256 at 10,000 and 100,000 elements 0.14 and 0.26, keyed
mutation 0.64, and constrained maintenance 0.45 seconds.

Static analysis reported zero diagnostics across the runtime source, the live test modules, and
all fifteen demo modules; 77 Python contract tests pin the source and demo shapes. Every packaged
VBA module round-tripped byte-for-byte. The fifteen demos executed 144 practical examples without
an Office or VBE popup, and every rendered worksheet passed visual review. The new query demo
counts 50,000 rows server-side in 0.04 seconds against a 5-second gate.

Host boundaries

VBA reserves Kill for its file-deletion statement, so a session terminates through
KillProcess, joining Connect, Disconnect, YieldOnce, IsIn, and SingleItem. VBA also
keeps one global casing per identifier, so declaring a lowercase name anywhere rewrites every
bare Name in the project and breaks bang syntax against a case-sensitive column lookup; a source
contract now refuses that declaration. Neither is visible to static analysis, and both were found
by the live compiler.

Execution and network contract

Tasks remain cooperative on Excel's thread, and ROneCOne makes no VBA parallelism claim. A query
executes through the existing provider path, so its failure detail and cancellation behavior are
unchanged. A session owns kernel32 pipes directly and polls them cooperatively. The network is
touched only by the HTTP client, and only for URLs you request: the runtime never phones home,
sends no telemetry, and requires no VBIDE trust, installs, or references. The HTTP demo and the
HTTP test contract are the only release gates that need internet access; the query, process, and
JSON demos run offline.

Import ROneCOne.cls to begin, or open the Query demo to watch a LINQ expression become SQL
before it runs. SHA-256 checksums for every release asset are included with the download.

ROneCOne 1.7.0

Choose a tag to compare

@WilliamSmithEdward WilliamSmithEdward released this 25 Jul 00:08

ROneCOne 1.7.0

ROneCOne 1.7.0 connects VBA to the artifacts around a workbook. Zip archives open, extract,
and build through a pure-VBA engine that needs no Shell.Application and no .NET. Long-running
jobs write crash-durable, level-filtered log lines. A folder can be awaited: the next created,
changed, or deleted file resolves a task. And the text at integration boundaries is handled
exactly: URLs percent-encode and decode per RFC 3986, HTML encodes and decodes its entities,
and a shell command can now be fed standard input.

Highlights

  • ROneCOne.ZipFile mirrors System.IO.Compression: OpenRead lists and reads entries
    (Entries, GetEntry, and per-entry FullName, Name, Length, CompressedLength,
    ReadAllText, ReadAllBytes, ExtractToFile), inflating stored and deflated data with
    CRC-32 verification; CreateFromDirectory writes a store-only archive, and
    ExtractToDirectory unpacks behind a directory-traversal guard and never overwrites.
    Zip64, encrypted, and multi-disk archives are refused with the typed ROneCOne.ZipError.
    The inflate engine is pure VBA, built against fixtures covering every deflate block flavor
    and verified live against PowerShell Compress-Archive and Expand-Archive in both directions
  • ROneCOne.Logger(path, [minimumLevel]) writes UTC millisecond-stamped, level-coded lines
    through the composite formatter, with LogTrace through LogCritical, IsEnabled, and
    MinimumLevel; a sub-minimum call never touches the disk, and each written line is appended
    and closed so it survives a crash
  • ROneCOne.FileWatcher(folder, [filter]).WaitForChangeAsync returns a task that resolves on
    the next created, changed, or deleted file, snapshotting at call time and rescanning on a
    throttle while awaited; cancellation and timeouts compose like every other task
  • ROneCOne.Uri.EscapeDataString and UnescapeDataString follow RFC 3986 over UTF-8;
    ROneCOne.WebUtility.HtmlEncode and HtmlDecode cover the five named entities and numeric
    references through surrogate pairs; and Process.RunAsync gains an optional standardInput
    that is written and closed at start, so filters like sort see end-of-file
  • A fourteenth demo workbook walks the zip surface offline, and the files, HTTP, and process
    demos grow logger, watcher, escaping, and standard-input rows

Release evidence

Each of three fresh Microsoft 365 Excel processes passed 878 live assertions, including
central-directory parsing, stored and both Huffman deflate flavors, CRC mismatch refusal, the
entry-name traversal guard, PowerShell archive interop in both directions, logger level
filtering with re-read lines, watcher creations, changes, and deletions under wildcard
filters, escaping round trips through surrogate pairs, and stdin end-of-file semantics. All
ten suite benchmark scenarios met their release gates in every sample; the medians ran
invocation 0.11, collection 0.19, ordering 0.88, SHA-256 at 10,000 and 100,000 elements 0.19
and 0.36, keyed mutation 0.62, and constrained maintenance 0.52 seconds. The new zip demo
benchmark opened a PowerShell-deflated archive, inflated its 1,000-line entry, and summed the
lines in 0.004 seconds against a 5-second gate.

Static analysis reported zero diagnostics across the runtime source, the live test modules,
and all fourteen demo modules; 70 Python contract tests pin the source and demo shapes. Every
packaged VBA module round-tripped byte-for-byte. The fourteen demos executed 148 practical
examples without an Office or VBE popup, and all 57 rendered worksheets passed visual review.

Execution and network contract

Tasks remain cooperative on Excel's thread. The file watcher observes changes by rescanning
snapshots inside the scheduler as time passes, and ROneCOne makes no VBA parallelism claim.
The zip engine runs entirely in-process in VBA, with no Shell.Application and no .NET
component. The network is touched only by the HTTP client, and only for URLs you request: the
runtime never phones home, sends no telemetry, and requires no VBIDE trust, installs, or
references. The HTTP demo and the HTTP test contract are the only release gates that need
internet access; the zip, logging, and watching demos run offline.

Import ROneCOne.cls to begin, or open the Zip demo to watch an archive built, refused, and
inflated without a single reference. SHA-256 checksums for every release asset are included
with the download.

ROneCOne 1.6.0

Choose a tag to compare

@WilliamSmithEdward WilliamSmithEdward released this 24 Jul 18:02

ROneCOne 1.6.0

ROneCOne 1.6.0 closes VBA's three oldest text gaps. Timestamps become real values:
DateTimeOffset-style instants that parse full ISO 8601 and Unix epochs, convert zones through
Windows, and do calendar arithmetic. Text formatting becomes deterministic: a String.Format
grammar with invariant output on every machine, a linear-time StringBuilder, GUIDs, and
crypto-grade randomness. And XML joins JSON and CSV as a first-class exchange format, queried
with XPath and bridged both ways with typed DataTables.

Highlights

  • ROneCOne.DateTime mirrors DateTimeOffset: Parse/TryParse for ISO 8601 with offsets,
    UtcNow/Now/Today, Unix epoch converters both ways, VBA Date bridges, month-end
    clamping arithmetic, instant-ordered comparison across offsets, round-trip ToIsoString,
    and a token formatter; ROneCOne.TimeSpan carries signed durations with totals, components,
    algebra, and a d.hh:mm:ss text round trip. Windows performs every zone conversion per
    instant through kernel32; the runtime hard-codes no offsets and no daylight saving rules
  • ROneCOne.Strings.Format speaks the {index,alignment:format} grammar with G N F D X P
    specifiers and date tokens, always writing a period decimal separator and comma grouping;
    ROneCOne.StringBuilder() appends, formats, and clears without the quadratic slowdown;
    ROneCOne.Guid.NewGuid mints canonical version 4 GUIDs; ROneCOne.RandomNumberGenerator
    draws GetBytes and rejection-sampled GetInt32 from Windows CNG
  • ROneCOne.Xml wraps MSXML6 with its secure posture intact (DTDs prohibited, external
    references never resolved): Parse and Load with optional namespace mapping, nodes with
    Name, Value, GetAttribute, HasAttribute, Elements, SelectNodes,
    SelectSingleNode, and OuterXml; Xml.DeserializeTable lands row elements in a typed
    DataTable through the same deterministic inference CSV uses, and table.ToXml writes
    round-trippable element-per-column rows that omit database nulls
  • Failures stay typed: ROneCOne.FormatError covers every text-format rejection, and
    ROneCOne.XmlError carries the parser's line, position, and reason
  • Twelfth and thirteenth demo workbooks walk dates and XML offline, and the text demo grows
    invariant formatting, builder chains, and identifier minting

Release evidence

Each of three fresh Microsoft 365 Excel processes passed 819 live assertions, including ISO
8601 and epoch round trips, offset re-views, calendar clamping, machine-zone conversions,
composite formatting shapes, GUID structure, random-range uniformity, XPath navigation,
namespace mapping, DTD rejection, and both XML table bridges. All ten suite benchmark
scenarios met their release gates in every sample; the medians ran invocation 0.11, collection
0.20, ordering 0.95, SHA-256 at 10,000 and 100,000 elements 0.19 and 0.29, keyed mutation
0.48, and constrained maintenance 0.55 seconds. The three new demo benchmarks parsed and
formatted 1,000 timestamps in 0.04 seconds, extracted a 1,000-row XML table in 0.07 seconds,
and hashed 1,000 strings in 0.13 seconds, each against a 2.5-second gate.

Static analysis reported zero diagnostics across the loose source project, the disposable test
workbook, and all thirteen demo modules; 65 Python contract tests pin the source and demo
shapes. Every packaged VBA module round-tripped byte-for-byte. The thirteen demos executed 136
practical examples without an Office or VBE popup, and all 53 rendered worksheets passed
visual review.

Execution and network contract

Tasks remain cooperative on Excel's thread; HTTP transfers overlap inside WinHTTP's own worker
threads, and ROneCOne makes no VBA parallelism claim. The date, formatting, and XML engines
run entirely in-process, and every local time conversion is delegated per instant to Windows.
The network is touched only by the HTTP client, and only for URLs you request: the runtime
never phones home, sends no telemetry, and requires no VBIDE trust, installs, or references.
The HTTP demo and the HTTP test contract are the only release gates that need internet access;
the dates, text, and XML demos run offline.

Import ROneCOne.cls to begin, or open the Dates + Times demo to watch an API timestamp
become a value you can compute with. SHA-256 checksums for every release asset are included
with the download.