Skip to content

feat(sdk): complete the PP-M7 author contract - #51

Merged
CN059 merged 22 commits into
devfrom
agent/pp-m7-completion
Aug 28, 2026
Merged

CN059 merged 22 commits into
devfrom
agent/pp-m7-completion

Conversation

@CN059

@CN059 CN059 commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • complete shared lifecycle and security conformance vectors across Rust, real WASM, and the private TypeScript SDK
  • add explicit SDK migration, machine-readable UI registry, generated TypeScript builders, package declarations, and the WIT 1.2 lifecycle adapter
  • drive the TypeScript reference clock through the fixed QuickJS candidate without promoting it to a production dependency
  • record Linux behavior, isolation, package, RSS, cold-start, and corrected steady-state CPU evidence
  • build and validate the pinned candidate on Ubuntu, macOS, and Windows while running the full behavior/security suite on Linux
  • close the PP-M7 repository implementation milestone while retaining the ADR-0003 production no-go

Security boundaries

  • WIT remains the only host/guest contract source
  • exact nine-interface import allowlist; zero WASI ambient imports
  • all host capabilities still pass through PermissionBroker
  • unknown TypeScript errors lower to internal without message leakage
  • the TypeScript SDK remains private and CLI template/publication stay disabled

Verification

  • current TypeScript runtime candidate run 33155960160: Ubuntu, macOS, and Windows passed; Ubuntu executed all behavior/security/isolation vectors
  • Rust lifecycle/security vectors and real host/WASM suites
  • TypeScript typecheck, emitted ESM/declarations, Node contract tests, and dry-run package
  • fixed QuickJS component build plus seven behavior/security/isolation tests and package budget
  • StarlingMonkey comparison build on WIT 1.2
  • release one/ten instance resource evidence with a 3-second steady-state CPU window
  • warning-free Rust API docs, floatile-platform metrics tests, workspace fmt/check/clippy, and dependency policy

Production gates intentionally still closed

  • componentize-qjs #76 is open and unreleased
  • Windows/macOS stable resource measurements are not recorded
  • full distribution NOTICE and CLI build-license policy remain unresolved
  • the candidate component's extra init export has not received a production contract decision
  • ADR-0003 therefore remains no-go and this PR does not enable the TypeScript CLI template or publish TypeScript artifacts

Refs: PP-M7, ADR-0003, componentize-qjs#76

CN059 added 22 commits August 28, 2026 13:41
Cover every start/event and WIT guest-error combination from the shared lifecycle suite, and drive the real guest fixture and host runtime from those stable vectors.

Refs: PP-M7, FR-PLUGIN-01, F11, NFR-MAINT-01

Tests: cargo fmt --all -- --check; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked; RUSTC_WRAPPER= cargo test -p floatile-cli --test conformance_cmd --locked; RUSTC_WRAPPER= cargo test -p floatile-sdk --test conformance --locked; RUSTC_WRAPPER= cargo test -p floatile-runtime --test security sdk_lifecycle_errors_reach_the_host_as_rejections --locked

Unverified: TypeScript SDK consumer
Expose language-independent Broker denial, invalid patch, fuel, timeout, and memory isolation outcomes through the conformance command, and drive the real host security tests from the same vectors.

Refs: PP-M7, FR-PLUGIN-01, F11, NFR-MAINT-01

Tests: cargo fmt --all -- --check; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked; RUSTC_WRAPPER= cargo test -p floatile-cli conformance --locked; RUSTC_WRAPPER= cargo test -p floatile-sdk --test conformance --locked; RUSTC_WRAPPER= cargo test -p floatile-runtime --test security --locked

Unverified: TypeScript SDK consumer
Make the author SDK language and version explicit for the dual-language project model while preserving legacy Rust projects. Add a read-only-by-default migrate command with recoverable writes, stable diagnostics, and idempotent automation output.

Refs: PP-M7, FR-PLUGIN-01, F11, NFR-MAINT-01

Tests: cargo fmt --all -- --check; RUSTC_WRAPPER= cargo test -p floatile-cli --lib migrate:: --locked; RUSTC_WRAPPER= cargo test -p floatile-cli --test migrate_cmd --locked; RUSTC_WRAPPER= cargo test -p floatile-cli --lib project:: --locked; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked

Unverified: Windows filesystem failure injection during recoverable replacement
Document the executable SDK migration contract and version-axis boundaries, and make warning-free generated Rust SDK documentation a required Linux CI step.

Refs: PP-M7, FR-PLUGIN-01, F11, NFR-MAINT-01

Tests: git diff --check; cargo fmt --all -- --check; RUSTC_WRAPPER= RUSTDOCFLAGS=-D warnings cargo doc -p floatile-sdk -p floatile-sdk-macros -p floatile-ui-schema --no-deps --locked; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked

Unverified: GitHub Actions execution of the new documentation step
Serialize the authoritative Rust UI component registry through the CLI so TypeScript code generation, editors, and agents consume component, property, binding, event, and version metadata without a parallel handwritten list.

Refs: PP-M7, FR-PLUGIN-01, F11, NFR-MAINT-01

Tests: cargo fmt --all -- --check; git diff --check; RUSTC_WRAPPER= cargo test -p floatile-ui-schema registry --locked; RUSTC_WRAPPER= cargo test -p floatile-cli --test schema_cmd --locked; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked

Unverified: TypeScript generator consumption
Add a private TypeScript author package whose strict component props and builders are mechanically generated from the Rust UI registry. Keep runtime selection and publication gated while CI proves stale generation, type safety, and canonical IR output.

Refs: PP-M7, FR-PLUGIN-01, F11, NFR-MAINT-01

Tests: cargo fmt --all -- --check; git diff --check; RUSTC_WRAPPER= cargo test -p floatile-ui-schema registry --locked; RUSTC_WRAPPER= cargo run -p floatile-cli --locked -- schema ui target/floatile-ui-registry.json; node sdk/typescript/scripts/generate-components.mjs target/floatile-ui-registry.json sdk/typescript/src/generated/components.ts --check; pnpm --dir sdk/typescript typecheck; pnpm --dir sdk/typescript test; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked

Unverified: TypeScript Component runtime and GitHub Actions execution
Define the private TypeScript widget author surface and lower its errors to the exact WIT variants. Consume both shared lifecycle and security contracts so adapters cannot invent language-specific outcomes or leak arbitrary JavaScript exceptions.

Refs: PP-M7, FR-PLUGIN-01, F11, NFR-MAINT-01

Tests: pnpm --dir sdk/typescript typecheck; pnpm --dir sdk/typescript test; cargo fmt --all -- --check; git diff --check; RUSTC_WRAPPER= cargo check --workspace --all-targets --locked

Unverified: TypeScript Component runtime execution of lifecycle and security vectors
Synchronize the runtime spike with WIT 1.2 and enforce the exact nine-interface host import allowlist. Record reproducible behavior, isolation, package, and Linux resource evidence from the fixed upstream candidate without promoting it to a production dependency.

Refs: PP-M7, ADR-0003, componentize-qjs#76
Tests: FLOATILE_SPIKE_DISABLE_RUSTC_WRAPPER=1 FLOATILE_COMPONENTIZE_QJS_BIN=/tmp/floatile-componentize-qjs-76/target/release/componentize-qjs pnpm --dir spikes/typescript-runtime build:quickjs
Tests: FLOATILE_SPIKE_DISABLE_RUSTC_WRAPPER=1 FLOATILE_COMPONENTIZE_QJS_BIN=/tmp/floatile-componentize-qjs-76/target/release/componentize-qjs pnpm --dir spikes/typescript-runtime test:quickjs
Tests: FLOATILE_TYPESCRIPT_CLOCK_WASM=target/typescript-runtime-spike/clock-typescript-quickjs.wasm cargo --config 'build.rustc-wrapper=""' test --release -p floatile-runtime --test typescript_clock_spike resource_evidence -- --ignored --nocapture --test-threads=1
Unverified: Windows and macOS adapter builds, stable-state CPU, distribution license and NOTICE inventory
Compile the private TypeScript SDK to ESM with declarations and declaration maps, expose only dist package files, and execute contract tests against the emitted boundary. Keep the package private while adding the same build gate to CI.

Refs: PP-M7
Tests: pnpm --dir sdk/typescript typecheck
Tests: pnpm --dir sdk/typescript test
Tests: npm pack ./sdk/typescript --dry-run --json --cache /tmp/floatile-npm-cache
Unverified: registry publication remains blocked by runtime, cross-platform, and license gates
Add the private TypeScript lifecycle adapter that constructs the widget resource, preserves host-authoritative State updates, decodes the unified event stream, and lowers lifecycle failures without leaking unknown exceptions. Keep lifecycle callbacks synchronous because long-running work remains brokered through Operations.

Refs: PP-M7, ADR-0001, ADR-0004
Tests: pnpm --dir sdk/typescript typecheck
Tests: pnpm --dir sdk/typescript test
Tests: npm pack ./sdk/typescript --dry-run --json --cache /tmp/floatile-npm-cache
Unverified: adapter execution inside a selected production TypeScript runtime
Move the QuickJS reference clock onto the private TypeScript SDK lifecycle adapter and drive all six shared lifecycle error vectors through the generated component and Wasmtime host. Preserve the behavior, Broker denial, timeout, memory isolation, package budget, and StarlingMonkey comparison paths on WIT 1.2.

Refs: PP-M7, ADR-0003, componentize-qjs#76
Tests: FLOATILE_SPIKE_DISABLE_RUSTC_WRAPPER=1 FLOATILE_COMPONENTIZE_QJS_BIN=/tmp/floatile-componentize-qjs-76/target/release/componentize-qjs pnpm --dir spikes/typescript-runtime build:quickjs
Tests: FLOATILE_SPIKE_DISABLE_RUSTC_WRAPPER=1 FLOATILE_COMPONENTIZE_QJS_BIN=/tmp/floatile-componentize-qjs-76/target/release/componentize-qjs pnpm --dir spikes/typescript-runtime test:quickjs
Tests: FLOATILE_SPIKE_DISABLE_RUSTC_WRAPPER=1 pnpm --dir spikes/typescript-runtime build:starlingmonkey
Unverified: Windows and macOS adapter builds, stable-state CPU, distribution license and NOTICE inventory
Drive broker denial, invalid State Patch, fuel exhaustion, epoch timeout, and StoreLimits isolation from the shared security suite through the TypeScript component. Distinguish catchable JavaScript allocation errors from Wasmtime linear-memory failures and retain peer-survival assertions.

Refs: PP-M7, ADR-0003
Tests: FLOATILE_SPIKE_DISABLE_RUSTC_WRAPPER=1 FLOATILE_COMPONENTIZE_QJS_BIN=/tmp/floatile-componentize-qjs-76/target/release/componentize-qjs pnpm --dir spikes/typescript-runtime build:quickjs
Tests: FLOATILE_SPIKE_DISABLE_RUSTC_WRAPPER=1 FLOATILE_COMPONENTIZE_QJS_BIN=/tmp/floatile-componentize-qjs-76/target/release/componentize-qjs pnpm --dir spikes/typescript-runtime test:quickjs
Unverified: Windows and macOS adapter builds, stable-state CPU, distribution license and NOTICE inventory
Sum schedstat CPU time across every live thread under /proc/self/task so process metrics include Tokio and Wasmtime workers instead of reporting only the caller thread. Tolerate threads that exit during sampling and cover the behavior with active worker threads.

Refs: PP-M7, NFR-PERF-01
Tests: cargo --config 'build.rustc-wrapper=""' test -p floatile-platform metrics --locked
Tests: cargo --config 'build.rustc-wrapper=""' clippy -p floatile-platform --all-targets --locked -- -D warnings
Unverified: Linux kernels without procfs
Extend the release resource evidence with a three-second post-first-tick CPU window for one and ten TypeScript instances. Record the corrected Linux results and separate the embedded runtime license closure from the still-failing CLI build and NOTICE gates.

Refs: PP-M7, ADR-0003, NFR-PERF-01
Tests: FLOATILE_TYPESCRIPT_CLOCK_WASM=target/typescript-runtime-spike/clock-typescript-quickjs.wasm cargo --config 'build.rustc-wrapper=""' test --release -p floatile-runtime --test typescript_clock_spike resource_evidence -- --ignored --nocapture --test-threads=1
Unverified: Windows and macOS build/resource evidence; automated distribution NOTICE; full CLI license allowlist
Build the exact unmerged componentize-qjs repair from source on Ubuntu, macOS, and Windows, then generate and verify the Floatile WIT 1.2 TypeScript component. Run the full shared behavior and security host suite on Linux while keeping the candidate separate from production dependencies.

Refs: PP-M7, ADR-0003, componentize-qjs#76
Tests: workflow syntax and fixed SHA reviewed locally
Unverified: hosted-runner execution requires the pull request workflow
Match the pnpm/action-setup v5 reference already used by the primary CI workflow so GitHub can prepare the three candidate jobs.

Refs: PP-M7, PR #51
Tests: hosted runner setup failure identified in run 33149647506
Unverified: candidate build steps rerun after push
Use the Windows command shim when the TypeScript component builder launches the SDK package build, matching the existing local tool executable handling.

Refs: PP-M7, PR #51

Tests: node --check spikes/typescript-runtime/scripts/build-backend.mjs; pnpm --dir sdk/typescript typecheck; pnpm --dir sdk/typescript test; git diff --check

Unverified: hosted Windows candidate rerun after push
Allow Node 26 to execute the fixed pnpm.cmd build command on Windows while retaining direct executable invocation on Unix hosts.

Refs: PP-M7, PR #51

Tests: node --check spikes/typescript-runtime/scripts/build-backend.mjs; pnpm --dir sdk/typescript typecheck; pnpm --dir sdk/typescript test; git diff --check

Unverified: hosted Windows candidate rerun after push
Apply the Windows shell requirement to jco and tsc command shims while keeping native runtime executables on direct invocation.

Refs: PP-M7, PR #51

Tests: node --check spikes/typescript-runtime/scripts/build-backend.mjs; pnpm --dir sdk/typescript typecheck; pnpm --dir sdk/typescript test; git diff --check

Unverified: hosted Windows candidate rerun after push
Emit exactly one trailing newline from the UI builder generator so generated sources satisfy the repository diff hygiene gate deterministically.

Refs: PP-M7, NFR-MAINT-01, PR #51

Tests: RUSTC_WRAPPER= cargo run -p floatile-cli --locked -- schema ui target/floatile-ui-registry.json; node sdk/typescript/scripts/generate-components.mjs target/floatile-ui-registry.json sdk/typescript/src/generated/components.ts --check; pnpm --dir sdk/typescript typecheck; pnpm --dir sdk/typescript test; git diff --check origin/dev

Unverified: hosted candidate and primary CI rerun after push
Run the jco command shim through the Windows shell during component contract inspection while preserving direct execution on Unix hosts.

Refs: PP-M7, PR #51

Tests: node --check spikes/typescript-runtime/scripts/verify-component.mjs; node spikes/typescript-runtime/scripts/verify-component.mjs quickjs target/typescript-runtime-spike/clock-typescript-quickjs.wasm; git diff --check origin/dev

Unverified: hosted Windows candidate rerun after push
Record the completed dual-language author contract, shared adversarial vectors, migration and documentation gates, and reproducible three-host candidate build. Keep the production TypeScript runtime, CLI template, public SDK, and distribution explicitly disabled behind the unresolved upstream release and license gates.

Refs: PP-M7, ADR-0003, FR-PLUGIN-01, F11, PR #51

Tests: TypeScript runtime candidate run 33155960160; git diff --check origin/dev

Unverified: Windows/macOS stable resource measurements; upstream componentize-qjs release; automated license/NOTICE inventory; production handling of the extra init export
@CN059
CN059 marked this pull request as ready for review August 28, 2026 09:47
@CN059
CN059 merged commit d2ee4e0 into dev Aug 28, 2026
7 checks passed
@CN059
CN059 deleted the agent/pp-m7-completion branch August 28, 2026 09:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant