Skip to content

v0.11.4 — crates drill, multi-machine bounds, Node-free fallback

Latest

Choose a tag to compare

@phantomghost2023 phantomghost2023 released this 22 Sep 23:34
· 2 commits to main since this release

Four threads from the field, one release.

The canary triaged

The v0.11.3 wild run came back 8/11. All three red cells were legible:

  • npm/cli — upstream drift. Their committed package-lock.json is out of sync at HEAD; npm ci fails before any verifier runs. The matrix cell moves to microsoft/TypeScript (npm, synced lockfile, suite runs in their CI).
  • yarn-1 on react-router — upstream migration. Their HEAD now declares packageManager: yarn@pnpm@11.7.0; the tree the cell installs no longer exists. The cell pins the yarn-1 tree the local drill validated.
  • Python lifecycle on httpx — honest report. Discovery proposed tests.python from a layout that passes only through their no-dependency test helper; a plain-pytest claim cannot hold there. The lifecycle cell moves to pallets/flask, whose [tool.pytest.ini_options] the canary can read.

Two maintenance rows and one honest report — nothing reverted, exactly the split the workflow header promises.

The crates drill (sharkdp/bat, 316 locked crates)

Two bugs, both found only on the wild repo:

  • False positives (5 + 2 stale, 2.2%). Cargo registry dirs are name-version, and build metadata like toml-1.1.2+spec-1.1.0 contains dashes; last-dash splitting parsed such crates as name toml-1.1.2+spec, version 1.1.0. The split now resolves like cargo itself does: the earliest dash-remainder that parses as a full semver is the version. Healthy verdict after: ok: true — 316 crate(s) present, matching Cargo.lock in 17 ms, zero false positives; damage in registry/src + registry/cache flagged by name and repaired by cargo fetch.
  • A false negative. With a populated $CARGO_HOME and a vendor/ tree, deleting a vendored crate still verified ok: true — the shared registry cache masked the gap (the twin of the Go modules.txt hole). The vendored tree is checked on its own now (both cargo layouts), and the verdict follows the wiring rule: when .cargo/config replaces crates.io with the vendored sources, a gap is a build failure and answers no; an unwired vendor — bat ships a rustflags-only config — is spare evidence, the gap named without judging. The unwired cargo vendor damage test (deleted crate, no config) answers ok: true with the gap named; wired, the same damage answers ok: false.

observe aggregates across machines

Raise and tighten proposals now merge the committed ledger's per-machine history with the local tail, so a bound reflects the slowest machine's story: the comparator is the slowest machine's p90 against every other machine's p90, and tightening is refused when the local tail would flake the machine the ledger knows about. Ledger runs killed at the bound — which carry no duration — count as raise evidence instead of vanishing as no-data, and a raise must clear the bound that failed. One machine? Behavior unchanged.

A manual outlives Node

scripts/fallback/verify.py and scripts/fallback/brief.py: the smallest honest slice of manual verify for hosts with no Node — same manual/v1 frontmatter, command and expression checks (exit-code expectations, exists(), manifest(), lockActive()), npm/yarn-1/pnpm/venv/gomod lockfile comparisons with the same report-not-judge answers (other-platform entries skipped, uv-lock refusal honored), prerequisite satisfaction, and state.json stamps marked "tool": "python-fallback". No sandbox, no digests, no ledger — the banner says so every run. Proven on the demo repo (5/5 fresh, including the trap's exit-7 expectation), an npm fixture, and a Go checkout running its real 27-second suite under bash.

283 tests green. Full changelog in CHANGELOG.md; the drills and what they found in docs/WILD-REPOS.md.