113 Commits

Author SHA1 Message Date
Chris Tate 4e015e925f feat(updater): add native macOS app updates (#398)
* feat(updater): add native macOS app updates

- Add Ed25519-signed feeds, verified downloads, atomic replacement, rollback, and relaunch.
- Add manifest support plus key generation, feed signing, and updater ZIP packaging.
- Document and test the end-to-end macOS update workflow.

* fix(updater): harden macOS update lifecycle

* fix(updater): address review findings

* fix(updater): close review gaps

* fix(updater): bind installed identity and versions
2026-08-24 08:41:32 -05:00
Chris Tate 9540563761 fix(macos): align AppKit text runs to font ascent (#396)
* fix(macos): align AppKit text runs to font ascent

- Use each resolved font's ascent when converting engine baselines to flipped AppKit draw points.
- Apply the correction to direct, measured-line, and rect-based text drawing.
- Add regression contracts rejecting the old point-size anchor.

Co-authored-by: Sepehr Safari <25853688+sepehr-safari@users.noreply.github.com>

* fix(macos): align rect text fallback baselines

* fix(macos): align AppKit fallback text baselines

* fix(canvas): reserve fallback text ink headroom

- Prevent AppKit fallback glyphs from clipping at retained bounds.\n- Add regression coverage for top ink headroom and update geometry pins.

* fix(canvas): address text ink bounds and AppKit layout duplication

---------

Co-authored-by: Sepehr Safari <25853688+sepehr-safari@users.noreply.github.com>
2026-08-22 13:46:29 -05:00
Chris Tate dc0f64c1ea fix(ts-core): resolve installed compiler and SQLite modules (#389)
- Resolve scriptc through npm package resolution so nested, hoisted, and global sibling installs work.
- Generate a complete SQLite SDK module family and validate library imports against their actual directory.
- Cover global compiler lookup, documented event imports, and generated-core loading with regressions.
2026-08-18 08:59:46 -05:00
Chris Tate cb6a417965 feat(tray): add typed rich rows (#383)
* feat(tray): add typed rich rows

- Add typed metric, segmented-choice, and bounded chart rows across Zig and TypeScript.
- Render native macOS controls with command routing and accessible platform fallbacks.
- Support independently styled persistent menu-bar titles with configurable size, weight, and number style.

* fix(tray): keep rich rows model-owned

* fix(tray): harden rich row contracts
2026-08-17 23:26:25 -05:00
Chris Tate f6e4d99f09 fix(build): keep iterative app rebuilds local (#382)
* fix(build): keep iterative app rebuilds local

- Stabilize generated core and service ABI artifacts by content so implementation-only service edits never rebuild the app core.
- Split primary markup and app code into independently cached objects, reducing warm markup rebuilds to data compilation plus linking.
- Add rebuild explanations, phase timing/RSS summaries, and forward-compatible scriptc dev profiles through its published binary.

* fix(build): launch ScriptC correctly on Windows

* fix(build): address PR review findings

* fix(build): preserve cached app link inputs

* fix(build): invalidate cores on SDK module edits
2026-08-17 21:30:30 -05:00
Chris Tate 465a163e27 feat: add model-driven theme state (#378)
* feat: add model-driven theme state

- Add the TypeScript themeState helper across checker, generated ABI, and UiApp runtime.
- Preserve system accessibility behavior while supporting model pack, scheme, and accent precedence.
- Document the API and migrate gpu-components with runtime and replay coverage.

Co-authored-by: MohakBajaj <77928693+MohakBajaj@users.noreply.github.com>

* fix: constrain theme state optional fields

---------

Co-authored-by: MohakBajaj <77928693+MohakBajaj@users.noreply.github.com>
2026-08-17 08:51:57 -05:00
Chris Tate 393a0ed36e fix(app-runner): load manifest menus and commands (#376)
* fix(app-runner): load manifest menus and commands

- Resolve app.zon commands, menus, and shortcuts consistently across live and replay runners.
- Add zero-config TypeScript coverage, automation, and documentation.

Co-authored-by: MohakBajaj <77928693+MohakBajaj@users.noreply.github.com>

* test(app-runner): verify manifest menu registration

* fix(automation): escape menu snapshot catalogs

---------

Co-authored-by: MohakBajaj <77928693+MohakBajaj@users.noreply.github.com>
2026-08-16 23:04:07 -05:00
Chris Tate e8f9e4ee50 Fix large TypeScript Msg union compilation (#375)
- Derive comptime scan quotas from Msg shape and identifier bytes across generated shims, persistence, channels, and environment routing.
- Keep tag-skew diagnostics precise and teach future generated-code quota failures without blaming contracts.
- Add 160-arm compile/link and full TypeScript pipeline regression coverage.

Co-authored-by: Mohak Bajaj <77928693+MohakBajaj@users.noreply.github.com>
2026-08-16 21:46:23 -05:00
Chris Tate 1c1fba0c0f fix(macos): place fresh windows correctly (#369)
* fix(macos): place fresh windows correctly

- Separate restored, explicit, and default window placement from persistence policy.
- Honor explicit origins and restore policy across platform seams and both macOS hosts.
- Add placement coverage, update docs, and remove obsolete example workarounds.

* fix(macos): honor window placement policies

* fix(macos): correct window placement policies

* fix(macos): preserve window placement contracts

* fix(runtime): restore secondary window placement
2026-08-16 19:06:29 -05:00
Chris Tate 23d0f5908a feat(images): decode photos to fit runtime budgets (#366)
* feat(images): decode photos to fit runtime budgets

- Decode encoded photos to fit the app's registered-pixel budget across platform codecs.
- Add a validated 1-8 MiB app.zon image budget and independent 8 MiB source bound.
- Cover deterministic pixels, 1080p loading, replay, ABI plumbing, and documentation.

Co-authored-by: Sepehr Safari <25853688+sepehr-safari@users.noreply.github.com>

* fix(images): honor raised budgets across hosts

* fix(images): cover generated and non-mac hosts

* fix(images): harden source and replay limits

* fix(images): fit Android panoramas before validation

---------

Co-authored-by: Sepehr Safari <25853688+sepehr-safari@users.noreply.github.com>
2026-08-16 16:26:36 -05:00
Chris Tate ee63266095 Implement logical canvas radio groups (#361)
* Implement logical canvas radio groups

- Scope nested radios as one roving-focus, single-selection group.
- Align radio keyboard, pointer, and handler dispatch behavior.
- Expose radiogroup accessibility semantics and document the contract.

* Fix radio group accessibility edge cases

* Fix radio group focus traversal edge cases

* Fix radio group keyboard and naming semantics

* fix: preserve radio selection semantics
2026-08-15 18:36:17 -05:00
Chris Tate 474cb5e364 fix(core): pin scriptc tuple normalization fix (#356)
- Upgrade Native SDK compiler dependencies and generated references to scriptc 0.0.31.
- Add a real compiled-core ABI regression for bare-model and effect-tuple returns.
- Centralize test pin lookup and remove release numbers from comments and prose.

Co-authored-by: John Lindquist <36073+johnlindquist@users.noreply.github.com>
2026-08-14 17:27:26 -05:00
Chris Tate 0ecdc7d2e9 feat(core): expose model-declared windows to TypeScript (#351)
* feat(core): expose model-declared windows to TypeScript

- Add canonical TypeScript window descriptors with close-policy and close-command routing.
- Compile and hot-reload label-addressed secondary-window markup in generated launchers.
- Cover quit/hide behavior end to end and port the TypeScript system-monitor settings window.

* fix(core): harden TypeScript window declarations

* fix(core): validate TypeScript window views

* fix(core): validate returned window descriptors

* fix(core): harden TypeScript window contracts
2026-08-14 09:30:18 -05:00
Chris Tate e924d7fcac feat(examples): make the feed reader the end-to-end services showcase (#352)
* feat(examples): make the feed reader the end-to-end services showcase

* fix(examples): contain feed results in scroll pane

* fix(core): preserve service facade unbound metadata
2026-08-13 22:34:57 -05:00
Chris Tate 31d5b202bc feat(mobile): compile TypeScript cores and services for mobile targets (#346)
* feat(mobile): compile TypeScript cores and services for mobile targets

The external core and service compile drivers admit the pinned
compiler's three mobile triples — aarch64 iOS device and simulator
(macOS build host, iOS 15.0 floor) and aarch64 Android (any desktop
host, API 26 floor) — as library archives only, mapping the build
graph's Zig triples onto the compiler's own spellings and threading
the Android NDK location the way the graph already threads its zig.
The service executable lane refuses mobile targets with the
in-process pointer: no child process exists there, so the carrier
resolution turns "auto" into the in-process pool on iOS/Android and
teaches on an explicit "child", while desktop behavior is unchanged.

Mobile app builds stage a generated mobile entry beside the desktop
wiring: it satisfies the embed host's AppDef contract over the same
mirror, markup, and registry, drives the canonical mobile scene plus
the manifest's declared chrome, owns the service pool (markers and
stream relays live in the shim-installed app-data directory), and
delivers that directory through envMsgs. The compiled archives merge
into the embed static library the host tiers already link — flattened
to plain objects on Android, where Zig's ELF static-library emission
stores archive inputs as nested members the NDK link would skip.

A mobile execution lane (scripts/mobile-e2e.sh, NATIVE_SDK_MOBILE=1
in either gate tier) stages a battery over the service fixture's
compiled core and service archives, packages the fixture app for both
mobile targets and a services-free example for Android, then executes
the battery on a booted iPhone simulator and a headless arm64
emulator: typed pool results across update round trips, trap
isolation poisoning exactly one instance, and a journal replay that
reproduces the recorded model without initializing the archive. All
checks pass on both device classes. The TypeScript and services
chapters and the ts-core/ts-services skills state the mobile matrix;
persistence, boot images, and URL media caching remain unwired on
mobile.

* fix mobile TypeScript app wiring

* fix(mobile): validate TypeScript package outputs
2026-08-13 18:13:37 -05:00
Chris Tate baef0d96d3 feat(storage): harden file effects (#339)
* feat(storage): harden file effects

- Add bounded streaming reads, atomic write sinks, stat, and append effects.
- Gate external paths with symlink-safe filesystem permission checks.
- Preserve deterministic record/replay through content-addressed stream blobs.

* fix(storage): harden file effect lifecycles

* fix(storage): harden stream replay and key ownership

* fix(storage): keep stream sink on rejected chunks

* fix(storage): address file stream review findings
2026-08-13 14:10:10 -05:00
Chris Tate a7665807f3 feat(cores): compile TypeScript cores for cross desktop targets (#340)
The external core compile driver now enforces the same host/target
pairing matrix as the service compile lane: same-triple compiles keep
the native lane, Linux and Windows GNU targets cross-compile from any
macOS/Linux/Windows build host over the compiler's zig-cc lane, macOS
targets need a macOS build host, and every refused pairing teaches
before compiler work starts. The co-emitted contract sidecar is
target-independent: a macOS-native, x86_64-windows-gnu, and
x86_64-linux-musl compile of one staged tree emit byte-identical
documents with identical integer-class decisions, and the COFF and ELF
archives declare the same nsc_core_* symbol surface as the Mach-O one.

The SDK's fixture graph compiles corewire for the build host, so the
battery lanes configure under a cross -Dtarget, and a new
stage-cross-e2e step installs the host-fixture, markup, and in-process
service pool batteries under <prefix>/e2e for execution on the target
machine. scripts/cross-e2e.sh drives the lane end to end: it
cross-builds the batteries, the kanban example, and the service fixture
app (in-process carrier — the core and service archives linked into one
executable, with no defined-symbol overlap between the localized
service archive and the core's contract surface) for x86_64-windows-gnu
and x86_64-linux-musl, then executes the batteries on the Windows box
over ssh and in an amd64 Alpine container. gate.sh runs the lane in
either tier when NATIVE_SDK_CROSS=1 is set and skips it otherwise.

All three batteries pass on both targets: 29 host-fixture, 10 markup,
and 19 in-process pool tests on Windows (the three posix-spawn tests
skip there), and 32/10/19 in the musl container. The TypeScript chapter
and ts-core skill state the supported build matrix, including the Linux
glibc spelling and the unchanged desktop-only scope for mobile.
2026-08-13 01:28:42 -05:00
Chris Tate fe92cff10a feat(services): extend the in-process carrier opt-in to Windows and cross targets (#337)
* feat(services): extend the in-process carrier opt-in to Windows and cross targets

scriptc 0.0.28 localizes archive runtime symbols format-aware (ELF,
COFF, Mach-O) on every desktop host and for cross targets, so the
explicit `.service_carrier = "in_process"` opt-in no longer needs the
host-native macOS/Linux gate. Carrier resolution and the SDK fixture
lane's archive gate now admit the compiler's build matrix: Linux and
Windows targets from any macOS/Linux/Windows build host, and macOS
targets from a macOS host. Auto still resolves to the isolated child
carrier everywhere, and child stays selectable on every shape.

The service compile lane replaces its build-host-only refusal with the
same matrix. Same-triple compiles keep the native lane; admitted cross
pairings run the compiler's zig-cc lane (SCRIPTC_CC=zigcc,
SCRIPTC_TARGET=<triple>, and the build's own zig at the front of PATH
through the new --zig-exe argument); refused pairings keep a precise
teaching. The child executable's name follows the target OS instead of
the host's.

Cross Linux targets carry one encoded caveat: a bare `-gnu` spelling
lands on Zig's default glibc floor, which predates arc4random_buf — a
symbol the compiled service runtime references — so carrier resolution
teaches the `-gnu.2.36`+ (or `-musl`) spelling at configure time, and a
stated glibc version now rides the platform triple into the compile.
Windows targets link ws2_32, iphlpapi, and advapi32 beside the compiled
archives: the fixture modules get a shared helper, and the app lane's
Windows platform block adds advapi32 for the archive's CSPRNG.

Both carrier e2e suites pass natively on Windows (14 child-carrier
tests, 19 in-process pool tests: parallel keys, per-key FIFO,
cooperative cancellation and deadlines, trap isolation, streaming, and
replay), a macOS-built x86_64-windows-gnu service archive links and
initializes on Windows, and the linux-musl child executable and archive
cross-compile from macOS. The docs services chapter, packages page, and
ts-services skill state the widened opt-in and the cross-target scope.

* fix(services): align cross-target ScriptC archives

* fix(services): gate in-process archive architectures

* fix(build): keep ScriptC floor checks step-local

* fix(services): tighten cross-target toolchain gates
2026-08-12 23:51:19 -05:00
Chris Tate d7aeea1ea9 Promote credentials to core effects (#335)
* Promote credentials to core effects

- Add app-scoped TypeScript and Zig credential effects with capability and permission gates plus platform-backed storage.

- Redact credential journal results, synthesize deterministic replay placeholders, and provide hermetic devhost and test stores.

- Update checker diagnostics, mobile plumbing, SDK surfaces, documentation, skills, and conformance coverage.

* fix(runtime): harden credential effect lifecycle

* fix: harden credential effect handling
2026-08-12 19:21:30 -05:00
Chris Tate 8b2a97ffe7 feat(services): add the in-process TypeScript service carrier (#334)
* feat(services): add the in-process TypeScript service carrier

Compile src/services into a thread-instanced, runtime-localized library
archive (scriptc 0.0.27 library mode) linked into the app binary, and run
it on a small worker-thread pool: one archive instance per pool thread,
same-key requests strictly FIFO, distinct keys in parallel across
instances. The carrier preserves the child-process seam exactly — the
same HostCallBinding, poll-based completion delivery, journaled results,
lazy start, and replay that never initializes the archive.

Cancellation and deadlines ride the same cooperative marker-file token
the child publishes, with the same grace; an operation that ignores its
token is abandoned (thread detached, timeout routed, pool refilled), and
a detected trap routes kind service_trap through the per-instance panic
sink while other instances keep answering. Streaming chunks relay live
through a per-request framed file the pool's supervisor thread tails, so
chunks keep preceding the typed terminal mid-operation.

In-process is the default carrier on host-native macOS/Linux builds;
app.zon .service_carrier (and -Dservice-carrier) select explicitly, with
.service_pool_size (-Dservice-pool-size) setting the pool width (default
min(4, cores)). Windows and cross builds keep the child carrier.

corewire grows the two in-process projections (library facade entry and
compiler profile), the service compile script grows an --out-archive
lane, and bench-service-host now measures both carriers. The new pool
e2e suite covers success/throw routing, duplicate and unkeyed keys,
live streaming with cancellation, queued deadlines, parallelism,
per-key FIFO, trap isolation, the registry/archive pairing fence, and
journal replay against the pool.

* test(services): absorb runner load in the pool parallelism proof

One retry of the parallel batch keeps the timing assertion meaningful
on saturated runners; a pool that serialized distinct keys fails both
attempts deterministically.

* fix(services): harden in-process carrier supervision

* fix(services): harden pool queue scheduling

Wake the supervisor when newly admitted work can move the next deadline earlier, and scan the full queue so large busy-key bursts cannot hide runnable independent work.

* fix(services): drain streams after grace race

Let completion-owned requests remain in the supervisor stream polling path when the grace poison CAS loses, and cover the boundary with a deterministic regression.
2026-08-12 16:25:50 -05:00
Chris Tate 473cad71ef feat(storage): ship checked relational SQLite (#326)
* feat(storage): ship checked relational SQLite

- Add capability-gated SQLite effects, migrations, transactions, live queries, and replay across desktop and mobile.
- Validate schemas and named SQL at build time, generating typed command and subscription APIs.
- Add the relational notes flagship, documentation, tests, skills, and SDK mirror support.

* fix relational SQLite correctness gaps

* fix(storage): harden relational SQLite checks

* fix relational runtime policy parity

* fix sqlite tooling on node 22

* fix(storage): harden relational sqlite boundaries

* fix(storage): address relational review findings

* fix(storage): address remaining relational review findings

* fix(storage): address relational review issues

* fix(sqlite): retire stale live queries before replacements
2026-08-12 14:26:00 -05:00
Chris Tate 5fa8074f7c feat(bench): add service-host carrier benchmark (#329)
Measure the out-of-process TypeScript service carrier through its
production HostCallBinding against a bytes-echo service compiled by the
production service lane (frontend contract -> corewire host/registry ->
exact-pinned plain-scriptc executable). The echo operation returns its
request unchanged, so the numbers are the carrier's — lazy child spawn,
hello fence, framing, pipes, worker-thread queueing — not a workload's.

Scenarios: cold start (fresh host, first keyed request from admission to
polled completion, including the lazy spawn), warm round trips for 64 B
and 256 KiB payloads (p50/p90/p99), and queued throughput for N keyed
requests drained through the single worker thread.

Run: zig build bench-service-host -Doptimize=ReleaseFast
(requires node and npm ci in packages/core, like the services e2e lane).
2026-08-12 01:43:40 -05:00
Chris Tate 011caa9183 Upgrade scriptc to 0.0.26 (#325)
- Pin scriptc and its compiler/runtime lock data to 0.0.26.
- Refresh service contracts, compatibility fixtures, calibration, and documentation.
- Invalidate cached service frontends whenever the compiler manifest changes.
2026-08-11 22:38:24 -05:00
Chris Tate b7c493bab0 feat(ts-services): add typed boundary and ecosystem (#321)
* feat(ts-services): add typed boundary and ecosystem

- generate record-typed service clients/codecs and enforce hermetic 100% npm-static coverage

- run services in the devhost with native-format record/replay parity

- add typed streaming, cooperative cancellation, deadlines, fixtures, and guidance

* fix(ts-services): harden request admission

* fix(ts-services): align devhost runtime behavior

* fix(ts-services): enforce request deadlines
2026-08-11 21:25:48 -05:00
Chris Tate aa7ed9aa52 feat(storage): add SQLite-backed record store (#320)
* feat(storage): add SQLite-backed record store

- add capability-shed SQLite storage with deterministic effects, replay, and atomic record operations
- expose matching TypeScript and Zig APIs across desktop and mobile hosts
- add hermetic coverage, devhost support, documentation, and a worked example

Co-authored-by: carvalab <1446654+carvalab@users.noreply.github.com>

* fix(storage): restore pristine SQLite amalgamation

- restore the upstream byte removed during whitespace cleanup so the vendored source matches its documented checksum

Co-authored-by: carvalab <1446654+carvalab@users.noreply.github.com>

* fix(storage): harden store result delivery

* fix(storage): align devhost store semantics

* fix(storage): address review findings

---------

Co-authored-by: carvalab <1446654+carvalab@users.noreply.github.com>
2026-08-11 19:59:33 -05:00
Chris Tate 833e79e44a Implement the TypeScript service seam (#317)
* Implement the TypeScript service seam

- Classify src/services as ordinary static-tier TypeScript and generate a checked service contract.
- Compile, package, and supervise a pinned out-of-process service host behind Cmd.request.
- Cover service authority, failures, restart, timeout, replay, docs, skills, and showcase fixtures.

* fix service boundary validation and staging

* fix TypeScript service packaging and validation

* fix TypeScript service review findings
2026-08-11 14:23:22 -05:00
Chris Tate cafbf206e8 Implement model persistence (#316)
* Implement model persistence

- Add atomic engine-owned snapshots with generated codecs, restore and migration routes, backup recovery, debounce, and replay support.
- Gate persistence through app manifests and native check while keeping the TypeScript, Zig, and devhost surfaces in parity.
- Add store and end-to-end coverage, documentation, and a persisted TypeScript example.

Co-authored-by: carvalab <1446654+carvalab@users.noreply.github.com>

* Address model persistence review findings

* Address remaining model persistence review findings

* Fix persistence identity and restore route checks

* fix persistence replay and rollback safety

---------

Co-authored-by: carvalab <1446654+carvalab@users.noreply.github.com>
2026-08-11 13:01:01 -05:00
Chris Tate 4c95b04539 Improve retained desktop frame performance (#313)
* Improve retained desktop frame performance

1. Fix retained animation pumping and Windows frame wake scheduling.

2. Make latency and frame profiling monotonic, observable, and regression-tested.

3. Add physical-display-aware macOS and Windows performance gates.

* Fix PR performance and package checks

- Align NativeSdkViewInfo declarations with runtime GPU telemetry.

- Calibrate hosted macOS animation budgets without weakening physical-device defaults.

* Harden Windows performance sampling and shutdown

- Correlate physical hover samples with their responding visual frames.

- Stop due-frame callbacks immediately when the Windows host exits.
2026-08-10 21:22:03 -05:00
Chris Tate 7f6830a15b Polish component gallery interactions (#308)
* Polish component gallery interactions

- Fix keyboard navigation, scrolling, and focus-visible behavior across interactive canvas widgets.
- Rebuild gpu-components as an isolated TypeScript and Native markup gallery with complete interactive specimens.
- Add live model-driven Default and Geist theme switching with validation, documentation, and smoke coverage.

* fix component gallery focus and controls

* Fix TypeScript setup for component smoke CI
2026-08-10 12:32:31 -05:00
Chris Tate a727b1db68 Add customizable macOS DMG packaging (#304)
* Add customizable macOS DMG packaging

- Build polished drag-to-Applications archives with Retina-aware generated or custom backgrounds.

- Add manifest controls for Finder geometry, positioned items, files, directories, and links.

- Correct default optical alignment and document the packaging workflow.

* Fix DMG package validation gaps

* fix(packaging): make DMG generation reliable

* Validate TIFF payload ranges

* fix: tighten dmg validation and staging
2026-08-10 01:00:54 -05:00
Chris Tate 7e3a3157d0 feat(core): support streaming fetch responses (#300)
* feat(core): support streaming fetch responses

- Add a typed line-streaming Cmd.fetch overload and carry it through the command wire and runtime host.

- Keep stream lifecycle deterministic with loud cancellation and duplicate-key rejection.

- Cover the feature with contract, conformance, runtime, compiled-core, harness, example, and documentation updates.

* feat: stream AI chat through Vercel gateway

- Render chat-completion SSE deltas as they arrive.
- Pin the example to Vercel AI Gateway with official key config.
- Cover streaming, failure, and replay paths end to end.

* feat: add streaming fetch and chatbot example

* feat(chatbot): refine streaming chat experience

- Add a compact live model picker and immediate Stop action.

- Improve conversation layout, prompt focus, and caret retention.

- Expand chatbot documentation and end-to-end regression coverage.

* fix: harden streaming fetch limits

* fix: harden streaming fetch and textarea behavior

* fix(canvas): render lifted rich text
2026-08-09 21:02:29 -05:00
Chris Tate 283ab804c0 Add cross-platform audio capture and voice memo example (#303)
* Add cross-platform audio capture and voice memo example

- Add microphone and system-audio capture effects for macOS, Windows, and TypeScript core.
- Add a polished voice memo example with private app-data WAV saving and playback.
- Document platform support and packaging requirements with runtime and conformance coverage.

Co-authored-by: Marcus Schiesser <17126+marcusschiesser@users.noreply.github.com>

* Fix audio capture teardown and permissions

Co-authored-by: Marcus Schiesser <17126+marcusschiesser@users.noreply.github.com>

* Fix audio capture lifecycle and metadata

Co-authored-by: Marcus Schiesser <17126+marcusschiesser@users.noreply.github.com>

* Fix audio capture lifecycle edge cases

Co-authored-by: Marcus Schiesser <17126+marcusschiesser@users.noreply.github.com>

* fix: harden audio capture lifecycle

Co-authored-by: Marcus Schiesser <17126+marcusschiesser@users.noreply.github.com>

---------

Co-authored-by: Marcus Schiesser <17126+marcusschiesser@users.noreply.github.com>
2026-08-09 17:09:23 -05:00
Chris Tate 83a7aee721 fix(macos): smooth dialog backdrop blur (#299)
* fix(macos): smooth dialog backdrop blur

- Replace the flat box blur with an optimized three-pass Gaussian approximation.

- Preserve shadcn-compatible blur and scrim values while covering the host path with a build check.

* Fix macOS backdrop blur invalidation
2026-08-08 20:11:39 -05:00
Chris Tate bfcc5ff8df fix(kanban): polish packaged board interactions (#297)
- Resolve boot image assets from packaged macOS bundle resources so agent avatars render after launch.
- Keep drag landing motion above swimlane clips while preserving clipped neighbor reflow.
- Double the seeded Jira-style tickets and remove issue glyphs from card metadata.
2026-08-08 16:41:23 -05:00
Chris Tate 4269233703 feat(examples): make kanban an agent ticket board (#295)
* feat(examples): make kanban an agent ticket board

- Add numbered agent tickets with OpenAI and Claude avatars from SVGL.
- Simplify the titlebar to an icon-only add action.
- Keep drag geometry and end-to-end coverage aligned.

* fix(examples): make kanban columns scrollable
2026-08-08 14:26:34 -05:00
Chris Tate b230b140b8 feat(core): add native drag and drop to TypeScript apps (#285)
* feat(core): add native drag and drop to TypeScript apps

- Carry native file drops and widget drag events through the TypeScript core contract.
- Rebuild Kanban in TypeScript with animated reordering, cross-column moves, and Escape cancellation.
- Add runtime, ABI, rendering, end-to-end, documentation, and example coverage.

Co-authored-by: John Lindquist <36073+johnlindquist@users.noreply.github.com>

* fix: correct canvas drag lifecycle

* fix: harden canvas drag dispatch

* fix drag lifecycle and preview rendering

* fix(runtime): preserve drag gesture arbitration

---------

Co-authored-by: John Lindquist <36073+johnlindquist@users.noreply.github.com>
2026-08-08 13:22:16 -05:00
Chris Tate d26428e11b TypeScript cores compile through the external compiler by default; the TS-to-Zig emitter is deleted (#271)
* feat: add a check-only frontend mode

- The @native-sdk/core CLI without -o checks the core (and writes the contract when asked) and emits nothing.
- native check runs the frontend in check-only mode; no scratch emission under .native/check.

* feat: TypeScript cores compile through the external core compiler by default

- The transpiled lane is gone: src/core.ts builds through the external core compiler with nothing stated, and core_compiler = "transpiler" is refused with a teaching naming the release that removed it.
- Mobile targets with a TypeScript core are taught before lane selection: TS cores are desktop-only until the external toolchain grows mobile targets; Zig/markup cores stay fully supported on mobile.

* feat: retarget the TypeScript-core suites to the compiled lane

- test-ts-core-e2e compiles every fixture core through the external core compiler in the build graph (no env gating; the compiler is a package dependency), with the markup battery in its own binary — one archive per process is the C-ABI contract.
- The paired/byte-compare machinery is gone (paired_core, gen_paired, extract.zig, test-contract-equivalence, test-compiled-core-parity); the conformance suite pins mirrors over frontend contracts and committed goldens, and the new test-external-core-abi suite holds the ABI laws over a real archive.
- The soundboard core-only dispatch budget is re-measured for the compiled lane (~5.3us on an M-class laptop, Debug; the C ABI crossing plus snapshot decode) and stays pinned at 1ms.

* feat: carry the mixed pair-return idiom on the compiled lane

- The contract sidecar gains additive init_returns_bare/update_returns_bare facts, and the generated facade narrows `Model | [Model, Cmd<Msg>]` returns (a tuple carries its command; a bare model the empty buffer).
- The scaffold starter bounds its counters with literal comparisons so the compiler's integer range proof takes them.

* feat: delete the TS-to-Zig emitter

- The transpiled lane's machinery is gone: emitter.ts (11.9k lines), the rt.zig kernel, the run1k gate, and the emitter/effects/run-fidelity suites; execution truth lives in the ts-core e2e batteries over real compiled archives.
- The frontend (transpile.ts -> frontend.ts) checks and emits the contract sidecar only; the CLI refuses -o with a teaching naming the release that removed the emitter.
- The conformance corpus and grammar matrices re-adjudicate: emitter-only gates (97 corpus cases, 7 matrix rows) are marked as accepted with their former emit-time rules kept readable.

* fix: ship the compiled lane in the npm CLI payload

- copy-framework mirrors packages/core/compile-surface + scripts and tools/corewire (the build compiles corewire from the dependency); the sync and files lists follow.
- scriptc rides as a regular dependency of @native-sdk/cli, pinned equal to packages/core by check-version-sync, and the build graph resolves its entry by node's ancestor walk from packages/core.

* ci: the compiled lane rides the package dependency

- Every ts-core-building job gets the compiler with the one npm ci in packages/core; the separate compiler install, the archive/sidecar env plumbing, and the opt-in example step are gone.
- The parity job becomes Core Compiler Fences: stage-core-contracts plus the determinism-fence negative control (the positive batteries ride zig build test in the Zig Core job).
- No compiler cache action on purpose: hosted runners are ephemeral, so runs stay hermetic by machine lifecycle.

* docs: the compiled lane is the documented truth

- The TypeScript docs, quick start, component pages, example READMEs, the scaffold templates, and the ts-core skill describe the check-and-compile pipeline; the eject-story and rt-kernel/frame-cap claims are gone, and the core dev loop is stated as restart-shaped with native dev --core for fast logic iteration.
- The evals grader checks cores with the frontend and grades ts harnesses against externally compiled archives through generated mirrors.
- The changelog fragment states the breaks deliberately: default lane switch, transpiled lane removed, mobile teaching, dev-loop latency, and the compiler dependency.

* fix: ownership.ts joins the frontend staleness set

- The checker, inference, and type layers import ownership.ts, so an edit there must re-run every cached check and contract step; the staleness array now carries it.

* chore: drop the unused TypeScript compat wrapper dependency (#274)

- Nothing imports the @typescript/typescript6 wrapper at run time — the frontend loads the exactly pinned @typescript/old alias directly — so the wrapper leaves both manifests and the lockfile.
- The version-sync check pins the alias on its own, the toolchain doctrine comments describe a stray consumer-tree wrapper (which resolution still ignores, as the twins' fixtures keep proving), and the prose pins follow the reworded doctrine.
2026-08-03 11:17:30 -05:00
Chris Tate 31c140e26f TypeScript cores gain an opt-in external compilation lane (#268)
* feat: emit the contract sidecar from the frontend

- packages/core emits core.contract.json directly from checked analysis (--contract), byte-identical to the extraction path, Wyhash identities included
- every corewire consumer (conformance shims, stage-core-contracts projections) now reads the frontend document
- test-contract-equivalence pins the two producers byte-identical per ts-core fixture

* feat: ship SDK declarations and the pinned external compiler

- generate and ship sdk/*.d.ts with the real tsc (freshness-pinned, ambient-clean), never hand-written
- add the external core compiler as the package's one exact-pinned runtime dependency and bump the compiled-core pin to 0.0.22
- promote the static compile surface into the shipped package (compile-surface/core.ts), one copy for fixtures and apps

* feat: opt-in external core compiler lane

- ts-core apps opt in via app.zon .core_compiler = "external" or -Dcore-compiler=external; the frontend still checks and emits the contract, corewire projects the compile entry/profile, the exact-pinned toolchain builds the archive, and the app links the generated mirror over it
- the staged module keeps the transpiler lane's exact shape, so the generated wiring runs unchanged over either lane
- env-gated example pin: soundboard-ts builds and tests on the lane in the compiled-core parity CI job

* fix: accept an argument-carrying external compiler command

- The compile driver took --compiler as one executable filename, so an interpreter-plus-script override failed with the missing-version teaching; a path that exists is taken whole, anything else splits on whitespace.

* fix: ship the compiled lane in the npm CLI payload

- copy-framework mirrors packages/core/compile-surface + scripts and tools/corewire (the build compiles corewire from the dependency); the sync and files lists follow.
- scriptc rides as a regular dependency of @native-sdk/cli, pinned equal to packages/core by check-version-sync, and the build graph resolves its entry by node's ancestor walk from packages/core.
2026-08-03 08:53:39 -05:00
Chris Tate 8fc933b9db fix(windows): accelerate gpu surface presentation (#258)
* fix(windows): accelerate gpu surface presentation

- Render retained binary canvas packets through Direct2D and DirectWrite.
- Preserve dirty-region updates and GPU effects with a safe software fallback.
- Wire and validate the renderer across supported Windows build paths.

Co-authored-by: Omer Shatzberg <131801941+oshtz@users.noreply.github.com>

* fix(windows): harden Direct2D presentation

* fix(sdk): separate GPU backend request types

* fix(windows): honor GPU surface fallback contracts

* fix(windows): scale transformed blur kernels

* fix: harden Windows GPU surface presentation

* fix(windows): harden gpu blur and caption sampling

* fix(runtime): bypass packets for software surfaces

* fix(windows): preserve precise gpu surface updates

* fix(windows): reconcile GPU presenter state

* fix: preserve retained canvas resources

* fix: preserve Windows canvas packet fidelity

---------

Co-authored-by: Omer Shatzberg <131801941+oshtz@users.noreply.github.com>
2026-08-02 15:59:44 -05:00
Chris Tate 8f1da1831b fix: keep Windows effect spawns hidden (#253)
* fix: keep Windows effect spawns hidden

- Pass CREATE_NO_WINDOW for background Effects.spawn children on Windows.
- Verify redirected child output remains available without an attached console.
- Document the user-visible Windows fix in a changelog fragment.

Co-authored-by: Omer Shatzberg <131801941+oshtz@users.noreply.github.com>

* test: run Windows effect spawn probe in CI

---------

Co-authored-by: Omer Shatzberg <131801941+oshtz@users.noreply.github.com>
2026-08-01 15:05:56 -05:00
Chris Tate 476173b6b5 docs: add canonical machine-readable routes (#248)
* docs: add canonical machine-readable routes

- Move documentation under /docs with permanent legacy redirects and explicit canonical metadata.
- Serve synchronized .md siblings and llms.txt from the canonical MDX sources.
- Gate redirects, metadata, sitemap entries, and internal links against SEO regressions.

* fix(docs): harden canonical route migration

* fix(docs): preserve query strings in legacy redirects

* fix(docs): preserve MDX content in markdown routes

* fix(docs): decode MDX string expressions
2026-08-01 14:14:25 -05:00
Chris Tate 04b97cc2b7 feat: add native code editor example (#245)
* feat: add native code editor example

- Add an editable syntax-highlighted code surface with robust selection, large-file rendering, and expanded language coverage.
- Add the declarative Code Editor example with folder navigation, previews, permanent tabs, inline rename, save, and multi-window support.
- Extend tree interactions, macOS folder picking, component docs, tests, and live WASM previews.

* fix: address code editor review findings

* fix code editor large-file stability

* fix: harden large code editor state

* fix: polish code editor interactions

* fix: title empty code explorer windows

* fix: stabilize code editor rendering

* fix: harden code editor edge cases

* fix: address code editor review findings

* fix: resolve remaining code editor review findings

* fix: harden code editing and click handling

* fix: balance code editor tree spacing

* fix: load code editor folders on demand
2026-07-31 20:09:24 -05:00
Chris Tate a59015a246 corewire --facade emits the complete compiled-core entry; hand adapters deleted (#244)
* Contract sidecar: carry authored payload member names and type origins

- The transpiler emits payload_members on each union (the authored member name of every single-payload arm) and a module-level type_origins table (the declaring module of every named contract-table type).
- The sidecar extractor reads both tables into additive fields: "member" on message and union arms, "origin" on type-table entries.
- The sidecar reader parses both as optional facts, so older sidecars keep reading clean.

* corewire --facade emits the complete compiled-core entry module

- The facade is now the generated twin of a hand-written adapter: it imports the author's core module, re-exports every named contract type from its declaring module, wraps init/update/subscriptions and the model helpers, and implements the full ABI dispatch surface (boot_cmd, the nine dispatch entries, the wired channel entries, subscriptions, model_snapshot, helper_call) over one committed model, with the inline wire codec and the guard-and-trunc wholeness proof at every i64-classed ingress.
- The profile designates the facade's own entries (init/coreUpdate, coreSubscriptions only when the contract subscribes), maps plain export names to prefixed symbols, and carries the contract's integer_slots through; --f64-slot demotes a named record slot to f64 across the whole invocation for values that reach the f64-exact boundary.
- The sidecar reader accepts the external compiler's additive synthesized marker on struct entries.

* Compiled-core lane builds from generated facades and profiles

- build_core.sh stages the generated entry module and compiler profile from zig-out/core-contracts (stage-core-contracts now installs core_profile.json beside the sidecar and facade, with the host fixture's Model.pastBytes carried as f64 — it holds 2^53 by design, past the honest i64 window).
- The five hand adapters, the shared wire codec, and the hand profiles are deleted: the generated facade carries the whole surface, and the parity batteries hold every byte to the transpiler lane.
- The conformance suite keeps the mirror axes (fingerprints, contract artifacts, envelope unpacking); the compiled side's encodings are proven at full behavioral depth by the parity batteries, whose entry the generated facade now is. The hand markup contract gains the member and origin facts.

* fix(corewire): harden generated facade contracts

* fix(corewire): harden facade dispatch projection

* fix(corewire): harden generated facade contracts

* fix: accept legacy sidecars in parity tests

* fix: close corewire facade gaps

* fix(corewire): avoid false subscription inference

* fix(corewire): preserve unbound name precedence

* fix(corewire): align effective facade contracts
2026-07-31 17:20:24 -05:00
Chris Tate 3636af4b45 fix: improve textarea editing shortcuts (#231)
* fix: improve textarea editing shortcuts

- Align Command and vertical arrow navigation with native multiline behavior.
- Add bounded undo and redo while keeping controlled text buffers synchronized.
- Cover retained runtime and markdown-viewer editing paths.

* fix: harden textarea editing behavior

* fix: harden textarea editor lifetimes

* fix(canvas): harden textarea history and navigation

* fix textarea wrap navigation and macOS undo menu

* fix textarea navigation and history edge cases

* fix textarea reconciliation failure atomicity

* fix(runtime): make canvas text history replay transactional

* fix: preserve textarea indentation and shift-click selection

* fix: harden textarea navigation and selection

* fix: harden textarea caret boundaries

* fix: harden textarea history and CRLF editing

* fix(canvas): keep carets outside CRLF boundaries

* fix(core): keep CRLF edits atomic

* fix(canvas): preserve CRLF editing boundaries

* fix(canvas): match native selection navigation

* fix(runtime): reroute compound textarea history events

* fix(runtime): normalize reconciled CRLF selections

* fix textarea left navigation across soft wraps

* Fix IME history across CRLF boundaries
2026-07-29 13:06:47 -05:00
Chris Tate 7b5b226fb2 ci: parallelize native example coverage (#212)
- Split native example tests across four build-graph-backed CI shards.
- Run the Windows web-layer audit in parallel while preserving the aggregate required check.
2026-07-26 00:59:21 -05:00
Chris Tate 5f48ec3f67 fix: respect layered webview cursors (#211)
- Yield macOS GPU cursor regions to higher-layer embedded webviews.
- Prevent canvas cursor updates from overriding WebKit link and text cursors, with regression coverage.
2026-07-25 21:51:26 -05:00
Chris Tate daefe82106 fix terminal macOS shortcuts (#208)
* fix terminal macOS shortcuts

- Map Option/Cmd navigation and Cmd+Delete to shell-native sequences.

- Route Cmd+V through the bracketed-paste-aware terminal input path.

- Add runtime and example regressions for modified keys and paste.

* fix terminal key release handling on macOS
2026-07-25 13:18:51 -05:00
Chris Tate beb1d8712a Compiled-core parity: every core fixture built externally and proven against the transpiler (#197)
* Add per-fixture compiled-core parity batteries and contract staging

- PairedCore lockstep module: a fixture's e2e battery runs over both lanes, byte-comparing commands, snapshots, subscriptions, channels, and helpers per cycle
- build.zig gains env-gated test-compiled-core-parity (per-fixture archive/sidecar pairs) and stage-core-contracts for external toolchains
- paired roots are generated from each transpiled module's own export surface, so channel detection never goes stale

* Compile the ai-chat core with an external toolchain and pass its battery

- adds a hand-authored adapter entry, core profile, shared wire codec, and a static restatement of the core module for library-mode compiles
- build_core.sh stages author sources with specifier resolution, readonly-array erasure, and byte-alias folding, then records cold and warm compile times
- ai-chat update always returns the [model, cmd] tuple and api.ts iterates bytes by index

* Compile the host fixture's core externally and pass its full battery

- hand-authored host-fixture adapter and profile: 53 arms, four record payloads, the boot command, and the model-gated timer subscription
- the fixture's update returns the [model, cmd] tuple on every arm
- staging drops any SDK type alias the author's own sources declare; the mirror conversion walk raises its comptime branch budget

* Corpus cores return the [model, cmd] pair on every update path

- soundboard and system-monitor update signatures drop the bare-model union arm; every return carries an explicit Cmd
- behavior is unchanged: the paths that produced no command now say Cmd.none

* Compile the soundboard core externally and pass its battery

- hand-authored soundboard adapter and profile: 19 arms, 35 model helpers, the chrome and env channels, and the frame/key channel ABI entries

- channel ABI entries take flat parameters and answer the contract's channel flags through their export suffixes, listed after the unconditional exports

- staging spells the SDK's event and text records as object-literal aliases so host-constructed channel arms carry value-stored records

* Compile the system-monitor core externally and pass its battery

- hand-authored system-monitor adapter and profile: 25 arms, 23 model helpers, the boot probe command, and the chrome channel

- the sample sorts are explicit stable insertion sorts and the byte scans index instead of iterating, both lanes over one source

* Compile the markup fixture's core externally and pass its battery

- Add the markup adapter, profile, and build_core.sh case: the corpus's
  first three-function-channel core (frame, key, and pinch).
- Add the markup compiled-core battery entry, the mirror image of the
  host one: the markup core pairs, the host fixture rides transpiler-only.
- Return the [model, cmd] pair on every markup update path so the
  contract's shape flags read from a declared return type.
2026-07-24 23:24:53 -05:00
Chris Tate 2209f022ee Live <terminal> sessions, and examples/workbench: a terminal beside a browser (#198)
* Bring libghostty-vt back behind a consumer-safe terminal_vt seam

- The framework module imports terminal_vt everywhere: a ghostty-vt wrapper where the dependency is safe to traverse, a stub (enabled=false) elsewhere
- Root builds resolve a lazy ghostty pin gated on being the build root, so consumers running this build script as a dependency never touch ghostty's graph
- Apps opt in via addAppArtifacts .ghostty_vt with their own pin; scaffolded builds keep the stub and stay free of harfbuzz/translate_c

* Live <terminal> sessions: the runtime-owned emulator behind a bound pty key

- terminal_session.zig: per-pty-key libghostty-vt sessions publishing resolved TerminalGrid snapshots, with the example tier's lossless outbound ring, query-answer write-back, key encoding, and theme-derived palette promoted into the runtime
- The effects engine grows a pty delivery tap (live drain and replay feed alike), so emulator state derives from exactly the journaled stream; outbound bytes ride the journaled ptyWrite verdict path
- The app loop installs the builder's terminal grid lookup, reconciles cols/rows from each element's laid-out frame into ptyResize, applies the scrollback source-wins echo, routes focused keys/IME text and wheel scrollback to the session, and dispatches on-terminal states

* Terminal session store tests: the element contract at the store seam

- Lookup-driven session creation, fed output as resolved cells, stdin-ordered write-back (keys, text, DSR answers), retained-ring flush, resize reconcile, scrollback source-wins, respawn reset, and wide-cell spacer backgrounds
- Fix the snapshot sizing multiply: @min against a comptime bound refines its result type, so the product needed explicit widening

* The terminal emulator is an app-owned pin, opted into per app

- Replace AppOptions.ghostty_vt with terminal_sessions: bool; the framework resolves the app's own lazy ghostty pin with the app module's target/optimize and the safe flags, so an app asks for live <terminal> sessions with one field instead of threading a module
- Drop the ghostty pin from this package's build.zig.zon: a pin here materializes into every consumer's package directory even when lazy and unused (measured 27 packages / 585 MB in a scaffolded app's package dir, now zero), so the toolkit's own builds always carry the terminal_vt stub
- Add src/terminal_session_tests_root.zig so an emulator-wired app build can run the session store's tests, which skip in this package's own suite

* examples/workbench: a live terminal beside a browser in one split

- Add the workbench example: a <split> with a <terminal pty={key}> pane and a browser pane (back, forward, reload, address bar), app-owned navigation history, and a hidden-inset titlebar with per-pane drag bands
- The app spawns a shell with fx.ptySpawn and binds the key in markup; no emulator wiring, key encoding, or grid plumbing lives in the app
- Register test-example-workbench, whose build also runs the runtime session store's tests since this build wires the emulator

* Document live terminal sessions and how a build opts in

- Terminal docs: the runtime owns the emulator behind a bound pty key, plus an "Enabling live sessions" section covering the app-owned lazy pin, terminal_sessions = true, and the terminal_sessions_enabled flag apps can gate tests on
- Add the changelog fragment for the live sessions, the opt-in emulator, and the workbench example

* Workbench: the shell owns the keyboard when the window opens

- Mark the terminal element autofocus, so typing lands in the live session without a click first — a terminal window's keyboard belongs to its shell

* Terminal runs measure the face they actually ink with

- Derive the cell width from a 16-glyph mono probe divided by its length — the advance a merged run walks — and leave it unrounded, so glyphs stay on the cells the painter's backgrounds, cursor, and selection draw from
- Carry the measurement seam on each run: a command's raster extent is its own declared bounds, and the estimator's 0.6 em mono pitch falls short of a wider host face (macOS resolves the mono id to the system monospaced face at 0.618 em when Geist Mono is absent), which sheared a full-width row's last cell to a two-pixel sliver
- Cover both with a painter test that paints a full-width row against a wide-pitch provider and asserts every run's bounds hold its ink

* Workbench README: what the divider drag does to focus

- `stty size` named as the visible proof that the pty re-grids with the pane

- the divider keeps the keyboard after a drag; clicking the terminal returns it
2026-07-24 23:17:56 -05:00
Chris Tate cce5359d5b corewire --profile: the library-mode compiler profile beside the facade (#196)
* Facade channel entries take the wire shape; the packer becomes nsc_core_pack_msg

- Each wired channel now exports a wire-shaped entry mirroring the ABI
  header's C declaration (bytes as buffers, u8 modifier booleans, the
  pinch phase as its declaration-order member index) that builds the
  event record, runs the channel-function gate, and packs the result.
- The produced-message-or-null packer moves to one export,
  nsc_core_pack_msg, freeing the nsc_core_<channel>_msg names for the
  wire shapes; conformance drives both surfaces.
- Wired channels fence their new facade declarations (event records,
  channel-function names, PinchPhase) against type-table collisions.

* corewire --profile emits the library-mode compiler profile

- emit_profile.zig projects the sidecar into the profile JSON: the abi
  block's mode symbols, an export map binding every attested facade
  export to its marshalled signature (wire-shaped channel entries
  included), and the contract-sidecar section with echoed generations
  and identity-getter symbols.
- The determinism block carries the SDK policy as release-pinned data:
  deny-fences over the ambient surfaces with teachings naming the
  sanctioned Cmd/Sub routes, the shared async teaching, and trap
  remediations; emission is deterministic byte-for-byte.
- main.zig grows --profile beside --out/--facade with the same staging,
  alias nets, and check-runs-everything discipline.

* Facade slices spell plain arrays; flattened records stay undeclared

- Sequence types spell T[] (the declaration site's readonly already pins
  immutability; the readonly-array operator has no contract projection).
- Single-use synthesized records flatten into their one arm literal and
  no longer take an interface or a named encoder, keeping the
  synthesized names free for consumers that re-derive them.
- The pinch wire entry's export-map signature drops a stray f64: six
  parameters, six marshalling classes.

* Name the string constraints by their enforcer in the profile test comment

- The teachings/remediations comment points at the loader's rules
  instead of restating provenance.

* Profile and facade carry the whole contract a library-mode consumer reads

- Export-map names keep the facade's fixed nsc_core_ spellings while
  symbols take the contract's prefix; the profile's entry is the facade
  path made relative to the profile's own directory, refusing pairs
  with no relative spelling; --profile alone runs the facade emitter's
  refusal checks.
- Facade entry stubs carry the contract's declared shapes (cmd-returning
  init/update return the [state, effect] tuple, subscribing contracts
  declare the subscriptions stub), the unbound facts also ride the split
  modelUnbound/msgUnbound consts, and the appearance/chrome/env channel
  conventions ride exported consts; the transpiler passes the split
  unbound pair through unemitted like viewUnbound.
- The determinism fence table pins to the 0.0.11 surface manifest: the
  wall clock (stdlib.date., perf_hooks.) and the process family join
  with teachings naming the journaled clock and host-delivered inputs.

* Harden the split-const, entry-path, and profile-string edges

- The transpiler refuses a modelUnbound/msgUnbound constant that is not
  a string-literal list: the names are reserved contract vocabulary, and
  a data const under them would emit references without a declaration.
- The facade fences the split unbound names only when their consts
  actually declare, so a contract type under either spelling projects
  whenever no collision exists.
- The profile's relative-entry resolution carries the environment map
  (drive-relative spellings resolve against the drive's own working
  directory), and a non-UTF-8 entry spelling refuses with a teaching
  before it can corrupt the JSON, with an emitter-side backstop.

* Declaration forms spell record storage; path and slot edges pinned

- The facade declares node-stored records as interfaces and value-stored
  records as object-literal type aliases, and the transpiler's type
  table learns the alias form (a struct exactly like an interface, with
  storage still decided by the promotion walk) — a contract emitter
  re-deriving storage from declaration form now lands on the contract's
  own classes.
- Profile-relative entry spellings convert separators only on Windows
  (a POSIX backslash is a filename byte), and the emitter's
  release-pinned note records why integer-slot declarations stay
  absent: the pinned prover demands inline wholeness proofs at every
  construction of a slot-declared shape and does not trust classed-slot
  reads, refusing spread updates, structural twins, and the facade's
  own constructors alike.

* Unbound vocabulary, singleton unions, and storage edges hold both ways

- The checker refuses references to viewUnbound/modelUnbound/msgUnbound
  as module data (the build reads them without emitting, so a reference
  would name a missing declaration), symbol-resolved to the module
  consts.
- A bare kind-tagged object literal classifies as a one-arm tagged
  union, never a struct holding a textual kind.
- The facade fences viewUnbound only when the const declares, refuses a
  record referenced by node and value at once (one declaration cannot
  state both storages), and refuses a host-constructed channel arm
  whose named record cannot flatten into the arm the host fills.

* Reserved-list references resolve by symbol; alias records stay whole

- The reserved-const reference check resolves through import aliases and
  shorthand value symbols, catching a renamed binding or `{ modelUnbound }`
  by what it declares rather than its spelling; the split pair joins the
  entry-only export set and the rename guard.
- Object-literal aliases classify as structs only when every member is a
  plain record property (identifier-named, annotated, non-optional);
  quoted or optional properties refuse as unsupported aliases instead of
  registering a struct with silently missing or wrongly required fields.
- A kind-tagged shape with an optional discriminator is no union: the
  source permits the untagged value, so the shape refuses instead of
  projecting a mandatory tag.

* Alias form pins value storage in promotion; false attestations refuse a profile

- markPromotions reads declaration form: an object-literal alias keeps
  its by-value layout however the Model reaches it (the alias spelling
  IS the value-storage form), while interfaces stay with the
  reachability walk; pinned with the value/pointer pair test and the
  emitted Zig compiles with a by-value model record.
- The profile is enforcement data, so a contract attesting
  deterministic: false or async_free: false refuses emission with a
  teaching naming the attestation — a compile under the fences attests
  true by construction, and emitting would move the contradiction
  downstream.
- The transpiler test suite gains pins for the alias/singleton/split-
  const behaviors landed this branch.

* Value-record aliases refuse the shapes value storage cannot carry

- NS1061 teaches the whole family at check time: the model root stays
  an interface, a model-kept alias holds scalar fields only (heap-backed
  fields would dangle across frame resets under the shallow commit),
  model arrays carry reference-stored records, identity comparison over
  a value record refuses (no reference to compare), and an alias that
  reaches itself by value refuses (no finite layout).
- Scalar aliases the model keeps directly and heap-carrying aliases
  outside the model tree stay clean; pinned across all six shapes in
  the checker suite.

* Entry roots keep their contract shapes; by-value recursion and wrapped identity refuse

- NS1062 teaches at check time when Model does not declare a record or
  Msg does not declare a kind-tagged union, whatever declaration form
  produced the wrong shape (a plain object alias, an interface Msg, or
  a tagged singleton Model), instead of failing inside the emitted
  module's dispatch and commit machinery.
- The by-value recursion walk covers every by-value node — value
  records and tagged unions alike — so a singleton union reaching
  itself refuses; arrays still break cycles by indirection.
- The identity-comparison guard unwraps union operand types and follows
  plain type aliases, so a nullable or alias-wrapped value record
  refuses the same as a bare one.

* Presence checks pass the identity guard; optional arms and class roots refuse

- The value-record identity guard fires only when BOTH comparison sides
  can carry a record at once: a nullable presence check compares the
  option and stays exact, so generated optional encoders and idiomatic
  null gates compile.
- An optional payload property keeps a shape out of the kind-tagged
  union classification (the source permits the absent member while the
  emitted arm would demand it; absence spells | null), so the Msg root
  teaches instead of requiring an unrepresentable payload.
- The entry-root shape rule covers class declarations: a class named
  Msg is a struct and refuses with the union teaching.

* Flattening stays a value move; the root seeds node storage; assertions cannot shed identity

- Synthesized single-use records inline only when referenced by VALUE:
  a node-stored payload keeps its named declaration and pointer in both
  projections, however its name is spelled.
- The model root seeds the node-stored set (reference storage by
  contract), so a value reference to it refuses as mixed storage
  instead of re-deriving as node downstream.
- The identity guard's other-side test is structural: an
  assertion-erased operand still counts as a record, so shedding the
  alias name cannot slip a value-record comparison past the teaching.

* Integer-fixture envelopes pack through nsc_core_pack_msg

- The mixed-class envelope test drives the packer under its own name
  and adds the wire-shaped key entry's nothing-produced route, so the
  integer fixture exercises both channel surfaces.

* Identity peels assertions; record writes, inert lists, and skewed splits refuse

- The value-record identity guard types the peeled operand expressions
  (assertions erase at emission), so a structural respelling on both
  sides cannot shed the record's name.
- Record fields have no in-place write in the emitted layout: mutation
  through a mutable interface or alias property refuses with the
  reconstruction teaching instead of emitting an unassignable store.
- The facade refuses model-kept value records with non-scalar fields
  and model sequences of value records, so corewire --check agrees
  with what the facade's compilers accept.
- The split unbound consts must restate viewUnbound's resolved facts
  exactly (unresolvable and missing entries both teach), and a
  reserved-list const declared in an imported module refuses whether
  exported or not.

* Identity stops at emission too; singleton unions claim syntactic literal tags only

- Equality emission gains the NS1061 re-derivation: a by-value struct
  operand stops the build with the identity teaching, so comparisons
  reaching emission through generic instantiation or erased assertions
  stop the same way the checker teaches directly (pointer records keep
  their identity ==).
- The checker guard reads each operand through both the peeled and the
  spelled view, so an assertion that NAMES the record refuses at check
  time as well.
- The singleton-union reading claims only a syntactic literal tag: a
  record whose kind field resolves through a named literal union stays
  the attested struct.
2026-07-24 20:01:29 -05:00