`cargo test --workspace` could not run at all: dependency resolution failed with "aws-types@1.3.16 requires rustc 1.91.1" on the 1.91.0 default toolchain, so the gate the project documents was dead. Making it run exposed a compile break and two wrong tests that had been invisible for months. Now green end to end: 143 suites, 3155 tests, exit 0. Toolchain - rust-toolchain.toml pins the DEV toolchain to 1.91.1. The published MSRV stays `rust-version = "1.91"` (the engine builds on 1.91.0); only tidalctl's AWS SDK chain needs the patch release, and it now declares that itself. Consumer crates migrated to the current engine API (clean cutover) - iknowyou-engine: `AgentPolicy` gained five m10 read/profile-override fields; the literal now spreads `..AgentPolicy::default()` as the engine's own doc example does, so future fields do not break it again. - forage-engine: `RetrieveResult` gained p1 `reasons`. The app builds its own candidate pool, so it now tags what it knows: PreferenceMatch for the preference-vector blend, SemanticMatch (with the seed item) for similar-to-saved, ExplorationBudget for pinned discoveries. - forage-engine: `url_to_item_id` folded into the u32 item universe. The engine narrows item IDs to a u32 slot in durable per-user state and rejects anything above u32::MAX rather than alias two items forever, so every add_item with a 64-bit FNV hash failed. 9 of 28 smoke tests were failing on this alone. - forage-engine: bridge items read the top-2 preference CLUSTERS via `query_vectors`, not the single centroid from `preference_vectors().get()`. Since m12 that accessor returns only the strongest cluster, so a tech+jazz user whose interests split into two clusters looked single-interest and never bridged. Falls back to top-2 dimensions when a user has one cluster. Reconcile tests corrected to the shipped contract - tidal/tests/m8p3_reconcile_production.rs asserted `3 + 5 == 8` for a windowed count after heal. `take_crdt_snapshot` deliberately keys signal contributions to ONE canonical contributor (ShardId::SINGLE) because signals are relayed from a single writer, so per-node attribution double-counted every replicated event on every reconcile. Merge is therefore LWW on (last_update_ns, score) plus PN-counter per-node max: nodes converge on the more complete accumulator. The old expectation was asserting the bug that fix removed. - Rewrote to assert convergence, count survival (not 0), and no inflation, and added `repeated_reconcile_of_converged_nodes_does_not_creep` - the regression guard for the creep itself, which nothing covered. Pre-commit hook unified - hooks/pre-commit dropped `-D warnings`: each crate's `[lints]` table is the source of truth (`clippy::all`/`unwrap_used` deny, `pedantic` warn), and the flag promoted ~58 deliberate pedantic warnings in integration tests to errors, making every Rust commit impossible. - It now lints all five tidal crates instead of path-matching `tidal/`, which silently skipped tidal-server, tidal-net, tidal-stress, tidalctl and applications/ - the rot above lived in exactly those crates. Ported the CODING_GUIDELINES file-length, println, and unsafe-SAFETY checks from the divergent untracked copy that this replaces. - CONTRIBUTING.md now documents the real commands and the toolchain/MSRV split. Fleet recovery and soak - scripts/restore-fleet.sh: the fail-closed selective restore, promoted out of an ignored tmp/ directory into the repository. Preflights retained storage, digest-pinned images, parked state, and aggregate plus per-PV-node scheduler headroom before the first scale; writes a durable transcript under tmp/restore-logs/ with structured start/error/rollback/complete events. - k8s manifests park the standalone store, the RF3 cluster, and the soak monitor at zero replicas with restore-fleet.sh as the only supported scale-up path. - soak-eval/soak-watch and the nightly CronJob fail closed on stale or missing restart evidence instead of silently skipping the restart-aware half of the gate. - docs/ops/capacity-planning.md corrects the RAM envelope to the real hot-tier formula and separates analytic totals from the measured process envelope.
69 lines
3.5 KiB
TOML
69 lines
3.5 KiB
TOML
[package]
|
|
name = "tidalctl"
|
|
version = "0.1.0"
|
|
edition.workspace = true
|
|
# Higher than the workspace floor: aws-config -> aws-types 1.3.16 declares
|
|
# rustc 1.91.1, and resolution fails workspace-wide below it. Declared here so
|
|
# the requirement is visible where it originates rather than only in a lockfile
|
|
# error.
|
|
rust-version = "1.91.1"
|
|
description = "Command-line inspector for embedded tidalDB instances"
|
|
license.workspace = true
|
|
|
|
# ── tidal-crate lint posture (single source of truth) ──────────────────────
|
|
# IDENTICAL block across tidaldb / tidal-net / tidal-server / tidalctl. These
|
|
# crates deliberately DO NOT inherit `[workspace.lints]`; they hold the embedded
|
|
# recommendation DB + its transport/server/CLI to a stricter correctness bar
|
|
# (`unsafe_code = forbid`, `clippy::all = deny`, `unwrap_used = deny`).
|
|
# `unwrap_used = "deny"` is kept per-crate rather than in `[workspace.lints]`
|
|
# because the workspace also hosts the example/consumer crates under
|
|
# `applications/` (not held to the engine's bar). Keep these four blocks BYTE-IDENTICAL.
|
|
[lints.rust]
|
|
unsafe_code = "forbid"
|
|
|
|
[lints.clippy]
|
|
all = { level = "deny", priority = -1 }
|
|
pedantic = { level = "warn", priority = -1 }
|
|
nursery = { level = "warn", priority = -1 }
|
|
# Justified allows (lossy numeric casts are pervasive + intentional in the
|
|
# ranking/scoring math; module_name_repetitions is idiomatic for the flat
|
|
# module layout documented in CLAUDE.md):
|
|
cast_possible_truncation = "allow"
|
|
module_name_repetitions = "allow"
|
|
unwrap_used = "deny"
|
|
|
|
[dependencies]
|
|
tidaldb = { path = "../tidal" }
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
# Backup/restore manifest integrity (m11p8) — the same hash the engine verifies
|
|
# WAL segments and snapshot artifacts with, so a tidalctl-written manifest and an
|
|
# engine-verified one agree.
|
|
blake3 = "1"
|
|
# Object-store (S3-compatible) export/import for the DR gate (m11p8 R2). Chosen
|
|
# over `rust-s3` because the AWS SDK shares the workspace's existing
|
|
# hyper/rustls/tokio tree (no native-tls / second TLS stack), and R2 is handled
|
|
# with `.endpoint_url(<account>.r2.cloudflarestorage.com)` + `.force_path_style`.
|
|
# `default-features = false` + `rustls` keeps the TLS stack aligned with the rest
|
|
# of the workspace (reqwest is already `rustls-tls`); `behavior-version-latest`
|
|
# pins the SDK behavior contract so an SDK minor bump can't silently change it.
|
|
aws-config = { version = "1.8", default-features = false, features = ["behavior-version-latest", "rustls"] }
|
|
# `rt-tokio` exposes `ByteStream::from_path` (stream a file body straight off
|
|
# disk on `put_object` — no whole-file read into memory).
|
|
aws-sdk-s3 = { version = "1.137", default-features = false, features = ["behavior-version-latest", "rustls", "rt-tokio"] }
|
|
# `hardcoded-credentials` exposes `Credentials::from_keys` so the env-var creds
|
|
# (AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY) become a static SigV4 provider.
|
|
aws-credential-types = { version = "1.2", features = ["hardcoded-credentials"] }
|
|
# S3 transfers run on a locally-built current-thread runtime ONLY when an --s3-*
|
|
# flag is given; the local-dir backup/restore path stays fully synchronous.
|
|
tokio = { version = "1", default-features = false, features = ["rt", "macros"] }
|
|
# Fresh staging dir for an S3 import (downloaded prefix -> temp dir -> the
|
|
# UNCHANGED verified restore reads it). Reaped when the restore returns.
|
|
tempfile = "3"
|
|
|
|
[dev-dependencies]
|
|
tidaldb = { path = "../tidal", features = ["test-utils"] }
|
|
|
|
[[test]]
|
|
name = "cli"
|