Skip to content

Unwrap the Res values, and make the manifest docs match the parser - #1

Merged
martin-k-m merged 1 commit into
mainfrom
harden/spool
Aug 21, 2026
Merged

martin-k-m merged 1 commit into
mainfrom
harden/spool

Conversation

@martin-k-m

Copy link
Copy Markdown
Collaborator
  • Unwrap the Res values, and make the manifest docs match the parser

Six real defects, all the same shape: a Res or an Opt used as if it were the
value inside it. twill 1.7's checker does not catch these, so each one was a
runtime error or, worse, a silent success.

- cmd_add took len() of validate_name's Res, so `spool add` died with
  "len expects a tensor, list, string, dict or bytes" for every name.
- materialise did the same to vendor.export and pkghash.verify, so a failed
  export and a failed integrity check both read as success.
- vendor.read_tree pushed read_file's Res into the array it hashes.
- vendor.walk and commands.prune indexed list_dir's Res as an array.
- materialise never created twill_modules/, so install printed "packages are in
  twill_modules/" and wrote nothing. Verified fixed: install in a project with
  no git-backed dependency now leaves spool.lock and twill_modules/README.
- spool list said "no spool.lock yet" when a lockfile existed and locked
  nothing. Keyed on the file now.

Two README claims were false against the parser. It said escape sequences are
not interpreted so a Windows path reads back byte for byte; toml.unquote
rejects a backslash in a basic string outright:

  $ spool list
  spool: spool.toml: line 3: expected a quoted string for entry

A literal 'single-quoted' string is the form that works, and the documented
subset did not mention literal strings at all. entry validation was undocumented
too. Also: nine manifests' comments and this README said entry shows in
spool list, and cmd_list never printed it. Made that true rather than editing
nine repos.

needs.md: 13 of 14 entries delivered on 1.7.1. Entry 1, the process interface,
stays blocked and is now verified rather than assumed: there is no subprocess
builtin, and every git path dies with undefined variable "run".
@martin-k-m
martin-k-m merged commit e4049c7 into main Aug 21, 2026
2 checks passed
@martin-k-m
martin-k-m deleted the harden/spool branch August 21, 2026 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant