writeonce/docs/stories/language-runtime-database/15-deps-package-manager.md
shoney.arickathil c0b0dbb846 docs: audit all markdown against the code, fix findings, flatten status folders
- README: shipped concurrency/HTTP/WebSockets sat in the roadmap as "not yet
  available"; "no package manager" contradicted [deps]; the deps example
  would not have compiled (the key IS the module name)
- runtime/README: leads with wovm, wo-rt.c demoted to a historical section;
  dropped 2 nonexistent recipes, crates/rt, @gc refcounting, 13 suites -> 18
- employee + log-watcher READMEs claimed "does not compile"; both are gates
- error catalog: +10 emitted codes incl WO-E250, the only diagnostic the
  shipped query surface raises; recorded why the sweep rotted
- language-surface: group-by parses, then the typechecker refuses it
- 00-code-review + 00-link-audit re-run; history kept, not rewritten
- 48 dead Rust-era exploration links de-linked rather than re-pointed (their
  prose names the retired plan by number); successor map -> discarded.md
- 08-project-structure: compiler/plan/ never existed; corpus has 9 dirs, 5 empty
- releasing.md: dropped a --draft step the workflow never had
- new docs/00-doc-audit.md: findings + disposition, incl one row where the
  audit was wrong and the doc it accused was right
- status folders removed: 34 stories flat, status only in frontmatter; 252
  links recomputed from resolved paths; board/board-views/structure retaught
- story 24 -> in-progress, since frontmatter is now the only truth
- new iteration 38: fs mutation verbs + net.connect, the two capability
  families no iteration owned
- new iteration 39: gofiber/fiber v3.5.0 parity study. The ledger called
  CSRF/sessions unblocked by iteration 34's HMAC, but the runtime has no
  source of randomness at all
- linkcheck skips .dev/.superpowers: 0 broken paths, 0 bad anchors

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-26 19:20:22 +02:00

3 KiB

iteration status
15 done

Iteration 15 — dependencies: wo.toml [deps], git fetch, wo.lock

Format: product/story-iteration-template. Part of Story — one language, one runtime, one database, one binary.

Inserted 2026-08-18. LANDED the same day (branch web-framework): all acceptance criteria met — just deps-accept 8/0 (cold fetch + lock, use and /sub, offline-when-locked with the remote deleted, lock-beats-moved-tag, --update-deps, drift/transitive/collision diagnostics WO-E106/E107, dep fn main never the entry, manifest shape). The enabler for code shared between writeonce repositories — the web framework (iteration 16) is the driving consumer.

Spec exists: 2026-08-18-web-framework-design.md section A is normative for this iteration. Plan: 2026-08-18-deps-package-manager.md (5 tasks: manifest inline-table + [deps]; resolver fetch/cache/lock; multi-root discovery + module mapping + entry restriction; the just deps-accept gate over file:// remotes; docs closeout).

Goals

  • A project declares exact-rev git dependencies in wo.toml [deps] (name = { git = "...", rev = "..." }); woc fetches them (via the git binary — no network code in the compiler) into .wo-deps/<name>/ and resolves use <name> / use <name>/sub into the dep's module tree.
  • wo.lock pins resolved SHAs: builds are reproducible, a moved tag is reported rather than silently followed, and a lock-satisfied build never touches the network.
  • Honest edges: transitive [deps] refused with a diagnostic (flat-only v1), dep/local module-name collisions diagnosed, a dep's fn main ignored, pub applies across the boundary exactly as across modules.

Acceptance Criteria

  • Given an app whose [deps] names a framework in a local file:// git repo, when woc <app> runs twice, then the first run fetches + writes wo.lock, the second builds offline from .wo-deps, and the built binary runs.
  • Given the dep's tag moved after wo.lock was written, when the app builds, then the lock wins and the drift is reported; woc --update-deps refreshes it.
  • Given a dep whose own wo.toml has [deps], or a dep name colliding with a local module, when the app builds, then each is a named diagnostic, never silent misresolution.

Out Of Scope

Registries, version ranges/semver solving, transitive dependencies (the successor's first fork), private-remote auth handling beyond what ambient git config provides, vendoring commands.

Proposed Solution

Manifest parsing extends compiler/bin/main.ml's existing wo.toml reader; fetch = Sys.command over the git binary; resolution plugs the dep root into the existing directory-as-module discovery. Fixtures under tests/ use local file:// remotes so the suite stays network-free.