Skip to content

Releases: beyond10x/ess

0.23.0

Choose a tag to compare

@github-actions github-actions released this 11 Sep 14:14

Added

  • Source ess/4 declares error wire names without merging semantic error identities.
    Native HTTP responses honor explicit codes and preserve the qualified-name fallback.

  • Typed command response fields can fill emitted event payloads through explicit
    response mappings. Source/4 requires complete payload ownership, including explicit
    generated fields; ordinary suite/8 and coverage suite/9 compare actual returned values.
    New error and response deltas use ess-diff/4.

  • Authored ess-scenario/2 setup establishes typed, isolated backend entity rows
    for subsequent real view assertions. The optional Rust/Go adapter capability
    uses suite/6 or coverage suite/7 with explicit report/2.

  • when_subject_state in ess/3 combines a declared held lifecycle state with
    input guards. Shared bounded coverage and actual identity/state view assertions
    distinguish equal input applied to different existing states.

  • Fresh conformance synthesis accepts --compact; ordered compact JSON plus one
    newline preserves decoded meaning and retains its own exact suite-byte identity.

  • Opt-in ess/3 binding accessors read two or three declared field segments from
    event envelopes. Struct/newtype traversal, Optional and union availability, and
    whole terminal values have bounded typed plans shared by native Rust and Go.
    Computed mappings and implicit session context remain unsupported.

  • Accessor observations use ordinary conformance suite/6 or declared-coverage suite/7
    with explicit report/2 execution. Ambiguous nested-Optional observations and
    conversions without a mechanical observation rule retain capability refusals.
    Existing source/1-/2 and conformance/4-/5 behavior stays unchanged.

  • Complete target failures for accessor models use ess-target-failure/3, including
    the new accessor-resource cause. Legacy models retain their existing failure
    formats and bytes.

  • Binding-local ordered selection adds first-match, occurrence-based exclusion and
    fallback over declared record lists, with whole-input admission and Rust/Go
    helpers for explicitly prepared host conversion results.

  • Periodic bindings declare host ownership, typed context/read inputs, fixed-rate
    timing, serial work and acknowledged stop. Controlled Rust/Go observations verify
    actual scoped occurrences; native generation retains the explicit host obligation.

  • Clock-reading newtypes retain encoding and origin requirements. Native and
    conformance Rust/Go normalize observed readings only with matching source/epoch
    authority. New cause, selection-plan and reading-contract deltas use ess-diff/3.

Fixed

  • Compact predicates refuse trailing Boolean syntax after a quoted literal and point
    to structured any, all or not. Rust, Go and browser admission agree.

  • Structured text comparisons preserve literal values across canonical round trips.
    Comparisons requiring the corrected text reader select suite/8 or coverage suite/9;
    earlier suite envelopes refuse those forms before execution.

  • Go list selection validates canonical primitive types and rejects incorrectly typed
    list members, including values after an otherwise valid first match.

  • CLI regression coverage verifies complete compiled view declarations reach both
    stdout and disk. Report adoption guidance distinguishes report/2 failure and skip counts.

  • Closed-enum outcome partitions can validate and synthesize witnesses without a
    fictional default. Missing and overlapping values are reported from the declared
    finite domain; unsupported or unknown domains retain conservative requirements.

  • Binding documentation describes enum membership only when the compiler reached the
    representation within its existing traversal bound. String-backed literals explicitly
    state that type invariants and external resources are not checked.

0.22.2

Choose a tag to compare

@github-actions github-actions released this 10 Sep 20:11

Documentation

  • Refresh the dated published-release observation to 0.22.1 while preserving the scope of
    earlier conformance evidence and the generated current-source support matrix.

Fixed

  • Shared Gates 0.1.1 requires exact automation authors on every post-baseline commit before
    scanning or receipt reuse. Local hooks also require exact bot author and committer.

  • Classify the two native xattr helpers explicitly in consumer discovery, without granting
    model support or changing the frozen initial accounting baseline.

  • Generated output accepts SELinux and SMACK access labels imposed by the platform. Foreign
    attributes, file capabilities, ACLs and overlay control attributes still refuse publication;
    metadata outside the ownership ledger is never silently discarded.

0.22.1

Choose a tag to compare

@github-actions github-actions released this 10 Sep 18:55

Fixed

  • The release gate is green at the tag again. 0.22.0 was tagged from a commit whose own
    task check failed — eleven ess-xtask tests — so its Release run published no archives, and
    0.21.0 had failed the same way. Two causes:
    • The three reviewed wire:RawSpecFile#/definitions rows in
      crates/edge/ess-xtask/src/consumer_coverage/reviewed-schema-metadata.json carried the
      definitions-container digest from before delivery: at_most_once. The container changed with
      that word and the rows were not re-reviewed. Re-reviewed here: the reason and the decision page
      still hold, and only the shape digest moves.
    • website/docs/status/where-this-stands.md states the workspace version inside the rendered
      support block, so a version bump that does not re-run cargo xtask support leaves
      support-check red at exactly the commit a tag points at. Re-rendered for this version; a
      release commit carries the re-render beside the bump.
    • fuzz/Cargo.lock still pinned the workspace crates at 0.21.0: the 0.22.0 bump did not touch
      it, so fuzz-check's --locked builds refuse at the tag. Updated beside the root lock.

0.22.0

Choose a tag to compare

@b10x-bot b10x-bot released this 10 Sep 12:27

Added

  • Bindings accept delivery: at_most_once for one attempt without redelivery. Loss remains
    possible, and the guarantee does not impose an idempotency obligation on the handler.
  • OpenAPI requires Idempotency-Key only for commands invoked by an at_least_once binding.
    AsyncAPI, documentation, graph and browser projections describe both delivery guarantees.
  • Conformance records BindingGap::DeliverySingleAttempt instead of synthesizing a redelivery
    for an at_most_once binding. Existing at_least_once scenarios remain unchanged.
  • BindingChange::DeliveryChanged reports changes between delivery guarantees. The published
    schema admits the new value; the format remains ess/1, with existing IR and digests unchanged.

Changed

  • Common source security and privacy checks use pinned public Gates tooling and
    signed local evidence. Bot delivery no longer requires an Atlas checkout.
  • The repository test runner declares the same compiler and wrapper profile as
    consumer qualification, so the compiled-provider regression runs with admissible evidence.
  • Consumer checks refuse drift in the ESS evolution preservation mapping before running
    expensive extraction and behavioral cases. Existing semantic eligibility remains unchanged.
  • CI disables the consumer-check lane by explicit operator request. Local task check
    and task consumer-check retain the complete consumer coverage exercise.

This source release was published without running gates, tests or binary packaging.

0.20.0

Choose a tag to compare

@github-actions github-actions released this 06 Sep 16:07

Added

  • Standalone TypeScript normalization from Plan::typescript(package) and
    normalize-generate --target typescript --package NAME. Generated ES2022 ESM
    packages execute formats 1–6 from exact JSON text, use bigint for exact integer
    representation, retain source pins and expose strict retained-base64 helpers.
    The fixed schema profile refuses unsupported constraints before generation;
    uniqueItems: true is explicitly outside that profile. Complete Rust/Go maps
    retain their bytes at the same generator version.
  • Authored ess/2 adds finite Binary64 fields, distinct from integer and decimal
    values. Model projection retains compiler-owned numeric locations; old authored
    formats and Binary64 map keys refuse at every declared type position.
    ess-normalization/5 requires explicit input paths and adds token-preserving
    binary64_literal constants and finite binary64 conversion/steps. Reference
    and generated Rust/Go preserve signed zero, subnormals and nearest-even rounding.
    Two typed Binary64 operands use IEEE equality; authored model predicates retain
    their existing Number comparisons. Complete format 1–4 generated maps remain
    frozen. Whole-system synthesis and conformance refuse unsupported Binary64
    before publication; TypeScript structural output reports the finite codec obligation.
  • Standalone model Rust/Go libraries now emit checked finite Binary64 wrappers.
    Original-token codecs preserve signed zero, subnormals and nearest-even rounding
    through supported aliases, recursive containers and unions. Rust requires
    source-backed Serde decoding; mixed declared-field/Binary64-extra records refuse
    before output. Existing non-Binary64 generated maps remain unchanged.
  • ess-normalization/6 adds explicit fixed string array preparation and checked
    position reads in the reference, Rust and Go targets. Declared boundaries
    preserve absence, turn null values/elements into empty strings, pad short arrays
    and discard excess tokens after strict lexical checks. Active policies require
    original JSON text. Format 6 retains target report 3; complete format 1–5 maps
    remain byte-identical at the same generator version.
  • Opt-in ess-conformance-report/2 separates passed, failed, error, unsupported
    and skipped counts, binding outcomes to the exact executed suite bytes.
    Rust/CLI also expose checked ess-conformance-run/2 detailed output; generated
    Go supports standalone report 2 and explicit strict execution. Suite versions
    1–4 retain unknown coverage, so these counts cannot establish complete
    conformance. Report 1 and diagnostic defaults retain their existing behavior.
  • Checked ess-openapi-import/1 envelopes retain original source identity and
    semantic accounting. Reloading verifies the source digest, normalization and
    derived interface before projection; constraints that cannot be preserved
    produce located gaps or refusals. Legacy ess-service-interface/1 readers
    retain their existing representation.
  • ess-normalization/4 explicitly captures selected JSON field, array-item or root
    tokens as canonical standard base64 before first-stage schema validation. Exact
    token spelling, duplicate members and huge numeric lexemes are retained inside
    captures; JSON grammar, Unicode and the 64-level depth bound remain enforced.
    Reference, generated Rust and Go expose strict base64-to-JSON entrypoints for
    separately checked retained-document composition. Decoded-value APIs refuse
    capture branches without original token bytes. Targets use report version 3;
    frozen legacy templates preserve formats 1–3 emitted bytes and file maps.
  • ess-normalization/3 model-owned stage roots, pinned to complete compiler
    provenance and explicit type selections. Plan::check_with_models and CLI
    --model inputs reuse checked model wire projections without duplicate schemas
    or trusted imported annotations. Rust and Go retain model sources and version 2
    target reports. Unevaluated model invariants refuse planning; existing Go pattern
    limits still apply. Versions 1 and 2 retain their bundle recipe representation.
  • Explicit ess-normalization/2 ordered string concatenation/joining, exact integer
    rendering, list concatenation, original collection indices, filtered mapping and
    first-match selection. The reference engine and generated Rust libraries preserve
    order, duplicate values and lazy selected-value evaluation. Version 1 refuses the
    new operations and retains its existing semantics and canonical representation.
  • Version 2 branch-specific binary64_inputs declarations and ordered
    binary64_to_integer conversion with finite multiply/minimum/maximum steps,
    nearest-even decoding and explicit out-of-range refusal. Undeclared numbers
    keep the exact JSON policy; signed integer scaling remains separately governed
    by its reject/wrap policy. Reference, CLI and generated Rust share the semantics.
  • Standalone Go normalization libraries from Plan::go(package, module), with
    typed operation bindings, offline pinned schema validation, exact integer and
    declared binary64 input policies, and complete source/file provenance. Native
    Go fixtures exercise old, ordered and numeric recipes against reference results
    and located refusals. The exact frozen base64 pattern used by model Bytes is
    qualified against the pinned reference through a shared ASCII, Unicode, padding
    and long-input corpus in generated Go and Rust. Every other selected pattern
    retains its source-located go_schema_pattern generation refusal.
  • ess generate schema normalize-generate exposes Rust, Go and TypeScript normalization
    libraries with explicit package/module identity and complete source provenance.
    It checks every branch and target before destination preflight, protects source
    inputs, and offers read-only planned-file drift checking through --check.

Changed

  • Composition documentation states the generated client's selected-operation and
    model-identity guarantees alongside its byte-buffer transport boundary. An
    executable downstream example shows compatible and incompatible payloads
    forwarded unchanged, with separate authority and endpoint/error controls.
  • Document the frozen normalization equality limitation: formats 5/6 compare two
    floating representations numerically even in an admitted Integer expression.
    TypeScript preserves reference behavior; mixed integer/floating operands retain
    integer eligibility refusal. Static Binary64 admission and output provenance
    remain distinct. This release does not tighten the core equality contract.
  • In this pre-1.0 minor release, ess_synth::{go,clap}::workspace return
    Result<Emission, TargetFailure>. Their new finite-codec failures use
    ess-target-failure/2; Rust/Web failure envelopes keep version 1 and old bytes.
    ess_conformance::{go,web}::emit, ConformanceSuite::to_canonical_json, and
    Runner::run now return Result with a located AdmissionError. Readers,
    model producers, direct typed suites and CLI routes reject Binary64 before
    artifact creation or target interaction, including sparse models with no
    generated scenarios. Existing admitted suite bytes remain unchanged.

Fixed

  • Specification admission checks complete expression paths, both operands,
    membership values and lexical collection bindings across invariant, command
    and view owners. Conformance reuses the same type rules while retaining its
    separate projection and witness limits; authored operand errors are distinct
    from unreadable paths.
  • Authored conformance commands refuse an explicitly selected directory with no
    immediate lowercase YAML inputs before writing artifacts or selecting a runner.
    Diagnostics explain shallow discovery. Omitted selections, direct files and
    committed suites retain their existing behavior.

Changed

  • Define execution recovery boundaries for interrupted apply and removal, manual
    drift and fresh observation. Current absence does not establish who removed a
    release. Applied-state modeling and executable recovery remain follow-on work.

0.19.0

Choose a tag to compare

@b10x-bot b10x-bot released this 05 Sep 22:36

Changed

  • Rust/Web workspace emitters and synthesis facades now return checked Result
    values. Complete ess-target-failure/1 refusals carry the neutral plan and
    source-located causes before any artifacts are written. Callers must handle the
    fallible API; successful plans and generated bytes retain their contract.
  • Sliced provenance uses the explicit slice-sha256/2: digest profile. Regenerate
    older sliced artifacts when adopting this release. Semantic diff/impact now
    accounts for previously omitted constructs, served views and reusable row shapes.

Added

  • Source-pinned normalization library with strict ess-normalization/1 recipes,
    explicit external dispatch, ordered input/output schema boundaries, separate
    missing/null behavior, lazy choices, case-sensitive string-prefix selection,
    signed-integer overflow policies, collection
    mapping and distinct-category counts. Every branch checks before reference execution.
    schema normalize-check checks and canonicalizes recipes; schema normalize-run
    executes an explicit branch without overwriting any input. The JSON text boundary
    refuses duplicate keys and numbers that cannot round-trip without precision loss.
    The Rust library API also emits standalone normalization crates with an
    ess-normalization-target/1 provenance report. Go/TypeScript normalization targets
    and a target-generation CLI remain pending; structural libraries are not application decoders.

  • Complete JSON Schema document-root import (schema import-document), preserving
    the root record, local definition closure and original source locations through
    validation and all three data targets. Explicit ess-schema-bundle/2 root identity
    is replay-checked; component-bundle /1 bytes remain unchanged. Conflicting root
    names, incompatible dialects and unsupported resource references refuse.

  • Direct ESS-model data realization (generate types) with explicit qualified roots
    or all-type selection. Reuses the existing schema wire mapping and shared native/TS
    targets, refuses wire-key collisions and records model versus bundle input provenance
    in ess-types-report/3. Model invariants, map-key validation and TypeScript nominal
    identity limitations remain explicit obligations, not silently claimed behavior.

  • Root-selected structural type planning over checked schema bundles and accounted
    Go, Rust and TypeScript data-only targets (schema types-bundle). Requiredness, nullable values,
    reference siblings, open objects and prefix tuples retain explicit shape, source
    provenance and runtime obligations. Native packages include presence-aware JSON
    codecs, exact number retention and explicit package/module identity in the versioned
    target report. Application decoder semantics remain separate from these structural targets.

  • Qualified schema-only component import with explicit JSON Schema 2020-12 interpretation,
    source-byte retention, complete local reference closure and persisted replay checks.
    schema import-bundle, project-bundle and validate-bundle do not fabricate a service,
    apply decoder defaults or silently accept unsupported schema semantics.

  • Authored site pages resolve links against explicitly included source documents and
    --asset UTF-8 downloads. --front-page preserves an override's source location;
    --strict-links refuses unpublished local targets with source-line diagnostics
    before output is written. Downloads share the existing output containment checks.

  • A source-backed format/digest catalogue and historical maturity outlook, together
    with preserved configuration and invariant planning from older worktrees.

Fixed

  • CI explicitly provisions the WASM compiler target required by generated-workspace
    feasibility checks, including the shared release gate.

  • Kubernetes imports reject malformed Secret shapes and redact failed subprocess
    diagnostics before credential-bearing values reach output.

  • CLI generation preflights complete destination sets, including composed outputs,
    to reject containment and alias collisions before writes.

  • Persisted delivery documents and standalone conformance reports validate claims
    through generic deserialization as well as explicit readers. Existing conformance
    formats remain current; the successor coverage formats are designs, not shipped APIs.

  • Checked infrastructure model transformations preserve owning handles and resolved
    reference membership. TypeScript projection checks one final binding namespace.

  • Rust/Web feasibility checks reject generated name, path, recursive layout and
    incompatible binding representations. Web dependency-module and outcome-arm
    buffer/encoder collisions are checked in their actual scopes; legal names elsewhere
    remain valid. Delivery-arm checks also account for the actual ordering of local
    bindings without rejecting legal first-input transformations. Web workspaces with
    no published events emit a valid empty event log. Supported Integer, Boolean and
    Bytes map-key decoders borrow nested diagnostic paths correctly in HTTP/Web output.

  • Specification validation refuses colliding effective wire field names across structs,
    entity identity/state/fields, command inputs, event/error payloads, view rows and
    separate view parameters before any projection can silently overwrite a property.

  • Long unbroken identifiers in authored prose wrap within narrow site viewports,
    including links and emphasized text; code listings retain horizontal scrolling.

  • Authored Markdown mermaid fences in generated HTML sites now use the bundled
    diagram renderer, just like generated diagrams. Other fenced code remains a
    listing, and diagram source remains escaped and readable without JavaScript.

0.18.0

Choose a tag to compare

@timofriedlberlin timofriedlberlin released this 04 Sep 14:08

Added

  • A specification's scenarios can be rendered as a page somebody presses play on.
    ess verify conform web emits a player: the scenarios on the left, a swimlane in the middle with
    one lane per actor and one row per act, and the state, the views and an optional device surface on
    the right. It is emitted for any specification and knows nothing about any of them — the page and
    the engine are static assets, and the only generated file is model.json, the projection the page
    reads.

    The reason to have it is that a specification nobody has run is a specification nobody has checked,
    and until now the only way to run one was to hand-write an implementation of it. Two exist —
    reference::Billing and reference::Oracle — and they exist so a generated suite has a
    known-good target, not so that every adopter writes one before seeing anything move.

    It replays rather than executes, and says so on the page. A scenario declares which outcome
    each command took; the player applies the effect the model attaches to that outcome. Every
    transition it shows is the model's — an outcome names its transition and the states it runs from —
    so a walk that stays legal says the specification is coherent, never that an implementation works.

    Three things the page keeps apart, because the model does: state is the truth now, a view
    is a projection with a filter, parameters and a consistency, and the UI is whatever a hand-
    written skin.js beside the emitted files renders. A view that selects nothing shows no rows; one
    whose parameter nothing has bound says which parameter it wants; an eventual one is allowed to be
    behind the state panel next to it.

    A binding's consequence is drawn in a lane of its own, dashed, because the model declares it and no
    scenario asserts it. That lane is where a command runs on nobody's grant, which is visible rather
    than argued about.

    assets/vue.esm-browser.prod.js is vendored unmodified with its licence beside it, the way
    assets/mermaid.min.js already is. No package.json enters the repository.

0.17.0

Choose a tag to compare

@github-actions github-actions released this 04 Sep 14:13

Added

  • A specification's scenarios can be rendered as a page somebody presses play on.
    ess verify conform web emits a player: the scenarios on the left, a swimlane in the middle with
    one lane per actor and one row per act, and the state, the views and an optional device surface on
    the right. It is emitted for any specification and knows nothing about any of them — the page and
    the engine are static assets, and the only generated file is model.json, the projection the page
    reads.

    The reason to have it is that a specification nobody has run is a specification nobody has checked,
    and until now the only way to run one was to hand-write an implementation of it. Two exist —
    reference::Billing and reference::Oracle — and they exist so a generated suite has a
    known-good target, not so that every adopter writes one before seeing anything move.

    It replays rather than executes, and says so on the page. A scenario declares which outcome
    each command took; the player applies the effect the model attaches to that outcome. Every
    transition it shows is the model's — an outcome names its transition and the states it runs from —
    so a walk that stays legal says the specification is coherent, never that an implementation works.

    Three things the page keeps apart, because the model does: state is the truth now, a view
    is a projection with a filter, parameters and a consistency, and the UI is whatever a hand-
    written skin.js beside the emitted files renders. A view that selects nothing shows no rows; one
    whose parameter nothing has bound says which parameter it wants; an eventual one is allowed to be
    behind the state panel next to it.

    A binding's consequence is drawn in a lane of its own, dashed, because the model declares it and no
    scenario asserts it. That lane is where a command runs on nobody's grant, which is visible rather
    than argued about.

    assets/vue.esm-browser.prod.js is vendored unmodified with its licence beside it, the way
    assets/mermaid.min.js already is. No package.json enters the repository.

0.16.0

Choose a tag to compare

@github-actions github-actions released this 04 Sep 13:13

Added

  • An authored scenario can claim a length of time. ess-scenario/1 could say what happened and
    in what order, and nothing about how long anything took: at: ordered the file and reached no
    runner. A migration of forty-five ACD scenarios into the format reported that as its one class of
    loss, and enumerated it — a twenty-second hold that is an experiment's independent variable, two
    wrap-up windows, a one-second queue-exit threshold, a one-minute callback TTL and a five-second
    teardown margin, all of them gaps between two instants and enforced by nothing. A system that
    fires every timer the moment it is armed passed every check ESS could write.

  • Three bounds, each on an anchor somebody wrote. An act names its instant with mark:, and a
    later act states what must be true of the gap: not_before: is the hold, within: is the
    deadline, and quiet: {for: …, events: […]} is the bounded negative. Every window names the
    instant it opens at, and there is no implicit anchor anywhere — the suite this was built for had
    negatives whose window opened wherever the preceding block happened to end, so inserting one
    arrangement step moved five assertions and no diff showed it.

  • at: is load-bearing at last. It still reaches no runner, and it is now what a duration claim
    is held against: not_before: PT20S in a file whose two instants are five seconds apart is a
    document saying two things, and it is refused rather than compiled into whichever one the compiler
    read first.

  • Six refusals, ESS-AUTHOR-028 to ESS-AUTHOR-033: a window measured from an instant nothing
    marked, one name for two instants, a window of no seconds, a bounded negative that forbids no
    event, a claim the timeline contradicts, and a window stating other than exactly one bound. The
    format now numbers thirty-three, and tests/authored.rs still holds a case per code and a case
    asserting the numbering and the documents agree.

  • Four steps and two target methods. mark_instant, expect_not_before, expect_within and
    expect_quiet join the closed vocabulary, which now has seventeen words. ConformanceTarget
    gains mark_instant and observe_elapsed, both with default bodies answering Unsupported, so a
    target written against the earlier interface compiles unchanged; the emitted Go runner asks for an
    optional Clock interface for the same reason. A target that implements neither reports the
    scenario unsupported, which §28 makes a failing run. There is no path on which an unheld
    window passes.

  • The clock stays the target's. A duration claim could have been built on wall-clock waiting,
    which makes every suite slow and flaky; on a logical clock, which most systems have none of; or on
    an observation reported after the fact, which on its own cannot make twenty seconds happen. This
    asks for the third and permits the first two to produce it: the suite states a length and the
    instant it is measured from, observe_elapsed says how much of the window to let close before
    answering, and the target reports a reading in milliseconds it stands behind. An end-to-end target
    waits; an in-memory target advances a clock it owns and answers instantly; the runner compares the
    reading with the claim and will not round towards it.

Changed

  • ess-conformance/3. The step vocabulary grew, which is a change to the shape of the persisted
    document, and that shape is exactly what a suite format versions. The reader this number is for is
    the one that would otherwise be worst off: an old Rust reader parses a closed tagged enum, so a
    3-shaped suite labelled 2 fails with unknown variant — a message blaming the document for
    the age of the tool. An old Go runner does not return a wrong verdict here; its step switch
    abandons a scenario whose first word it does not know and reports it skipped, which is the right
    answer reached by accident. SUPPORTED_SUITE_FORMATS keeps 1 and 2, because a 2 suite means
    in 3 exactly what it meant in 2. The committed suites under suites/generated/ are
    regenerated at the new number and are otherwise byte-identical.

Releases 0.16.0.

0.14.0

Choose a tag to compare

@github-actions github-actions released this 04 Sep 10:01

Added

  • A component can declare that its callers are people at a terminal. reached_by: command_line
    is a third answer to the question the other two already answer — where are the callers — and
    like them it names no wire, no port, no path and no verb. What it states is that the surface
    leaves the process as a grammar rather than as a call, which is the one fact neither
    in_process nor network can state: a command-line caller is deployed with the binary and is
    not a program.

  • A cli: block says where each accepted command sits in that grammar. Paths within a group are
    derived from naming.wire, as OpenAPI paths already are; grouping is declared, because which
    activity a command belongs to cannot be derived from anything the model holds. Eight refusals
    come with it, and they are the reason the tree is declared here rather than written beside a
    parser: a block on a component reached another way, a command-line surface with no block, a
    placed command the component does not accept, a placed view no domain it owns projects, an
    accepted command or a projected view the tree places nowhere, and either placed twice.

    The view half exists because of a defect found in a consuming repository rather than imagined
    here. connectors serves kubernetes.workloads from its personal-local daemon and has no
    command-line verb that reads a datasource at all, so an operator on that machine cannot reach a
    projection the process beside them is already publishing. Nobody wrote that down until somebody
    noticed. It is now a refusal at ess validate, before a tree is generated from a declaration
    that forgot it.

  • ess generate synthesize --target clap emits the grammar and the completion of it: a clap
    command tree, one flag per declared input field, a Handler trait carrying one obligation per
    word the tree places, and a completions verb that writes a script for every shell clap
    supports. An enum-typed field completes its whole closed set, so a shell completes the values
    a flag accepts and not merely the word in front of them; a field the model cannot enumerate
    completes as free text, because offering a guess would complete values the system refuses.

    It emits no type layer. The Rust target already emits every input, outcome, event and error as
    a type, and a fourth rendering of that layer would be a fourth thing to keep in step — so a
    handler receives clap::ArgMatches, and TARGET.md states that as a weakening rather than
    leaving it to be discovered.

    The format is still ess/1. Both additions serialize out when unset, so every existing
    document digests exactly as it did; the published schema grows by 93 lines and loses nothing.