Skip to content

v0.11.3 — bounds that age with the suite, and canaries that watch the wild

Choose a tag to compare

@phantomghost2023 phantomghost2023 released this 22 Sep 21:33
· 3 commits to main since this release

observe recalibrates bounds from history — and rewrites the measurement with them

A bound calibrated once at init is a snapshot; the suite it describes keeps moving. raise is the new middle direction between tighten and relax: when the worst run meets the bound or the 90th percentile crowds it (75%), observe proposes raising the bound while the claim is still fresh — before a busy machine turns a suite that drifted from 2s to 24s under a 30s bound into a false alarm. All three directions share one formula (3× p50, 1.5× p90, 1.1× worst), because two formulas can disagree about one series.

Every proposal — tighten, raise, relax — now also patches observation.measured_ms to the median of the accumulated history, with observation.samples and observation.measured_from: "verify history" as provenance. The claim stops advertising the single number init's probe took the day it was written.

The wild drills are release canaries

.github/workflows/wild.yml fires on release publish, monthly, and on demand — 8 builtin cells (pnpm/npm/yarn/bun on vuejs/core, npm/cli, react-router, oven-sh/bun; venv on httpx and flask; gomod on cobra and caddy — each cloned and installed by the ecosystem's own tooling) plus 3 lifecycle cells running the full init → probe → accept → verify path with the install performed by verify's prerequisite machinery. The one rule: a healthy tree must never be reported unsatisfied — and ok: null, correctly withheld, is a pass. test/wild.mjs is the checker; docs/WILD-REPOS.md documents every drill's false-positive rate and what it changed.

Discovery beyond package.json

manual init on spf13/cobra printed "0 candidate(s)" on a repo with a test suite — the tool shipped verifiers for eight ecosystems and proposed no claim about seven of them. Discovery now reads go.mod + _test.go globs (a testless module's go test ./... exits 0 having tested nothing, so it is not proposed), vendored-Go facts, pyproject/requirements/uv.lock and declared pytest. The Python install is chosen from the lockfile: uv sync --frozen, poetry install, or venv+pip. A repository-level go mod download prerequisite is declared when the module cache is empty — the one shared-location write discovery proposes, because a module cache is additive and re-derivable. The lifecycle canary now fails on "0 candidates": "proposed nothing" and "had nothing to propose" must not look identical.

Fixed: two bugs only a lifecycle could catch

  • A vendored Go tree was trusted on its manifest. Deleting vendor/github.com/spf13/pflag still verified ok: true — the vendor branch compared go.mod against vendor/modules.txt and never looked at the disk. Proven at caddy's scale (787 packages promised, one deleted, still "ok") before fixing: the manifest's package lines are checked as directories now (healthy caddy: 379 ms; damage: named). Same hole yarn-1's integrity check has; the lesson generalizes: a lockfile is evidence about an install, only the tree can confirm it.
  • A repo's own virtualenv never reached PATH on Windows. localBins() listed only .venv/bin; on encode/httpx a fresh venv was built, a 64 s install succeeded, and python -m pytest was still answered by the system interpreter. Both layouts are on PATH now.

277 tests / 52 suites green (11 new), own manual 5/5 fresh.