Skip to content

Support framework-native lane caches - #24

Merged
forhappy merged 17 commits into
mainfrom
codex/multi-framework-lane-cache
Aug 11, 2026
Merged

forhappy merged 17 commits into
mainfrom
codex/multi-framework-lane-cache

Conversation

@forhappy

@forhappy forhappy commented Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

What changed

  • make managed lane execution consume adapter-declared tool, cache, and private-output bindings instead of Cargo/npm-specific variables
  • support framework-native inheritance for Cargo, Go, pnpm, npm, Python virtual environments, and CMake build trees
  • initialize lazy cache namespaces safely, prefer project-local managed executables, and keep generated/private outputs out of source history
  • make execution finalization release only its own mount lease and report unmount failures without corrupting concurrent state
  • improve macOS NFS cache behavior and assert Cargo freshness from Cargo's machine-independent plain output
  • add a pinned real-repository A -> B -> C qualification harness, semantic evidence checker, checker tests, and opt-in CI matrix for all five non-Cargo frameworks
  • run the framework evidence checker's positive and adversarial contracts in regular CI
  • narrowly permit public lockfile literals in frozen, script-disabled built-in Node layers while retaining strict secret rejection elsewhere
  • document the public workflow, security boundary, adapter contract, and benchmark/evidence procedure

Why

Trail's environment model could describe non-Cargo frameworks, but managed commands did not consistently receive their exact executables, shared download caches, reusable immutable layers, or lane-private build outputs. On macOS, metadata-heavy build trees also paid avoidable loopback-NFS costs. That made a production A -> B -> C agent handoff rebuild or reinstall work that Trail already knew was compatible.

This change makes the active adapter generation authoritative. Successor lanes reuse only compatible artifacts: immutable dependency layers and download caches can be shared, source-sensitive compiled outputs are seeded only when their declared source closure matches, and Python/CMake outputs remain lane-private. Inactive adapters inject nothing, binding collisions fail closed, and secret-bearing or script-enabled Node installs cannot enter shared CAS layers.

Verification

  • cargo fmt --all -- --check
  • cargo check --workspace --locked
  • cargo clippy --workspace --all-targets --all-features --locked -- -D warnings
  • cargo test --workspace --locked --no-run
  • focused lane environment, managed execution, artifact policy, Cargo freshness, macOS NFS, and recovery tests
  • real local A -> B -> C evidence for Go/bbolt, pnpm/date-fns, npm/uuid, Python/httpx, and CMake/LevelDB
  • hosted five-framework evidence on product commit ea46277: successful workflow
  • fa4ec29 changes only regular-CI invocation; git diff --quiet ea46277..fa4ec29 -- trail trail-environment-adapter-sdk scripts Cargo.toml Cargo.lock README.md docs passes
  • current-head framework evidence checker contracts: successful Ubuntu hardening job
  • layered-workspace, FUSE, and macOS NFS conformance for the product commit: successful workflow
  • serial and parallel library tests, native storage/fault suites, Windows lane coordination, and ACP interoperability passed for the product commit
  • 1,024-case local property-test stress run for portable, order-independent artifact keys after CI found a generated Windows device name

The hosted evidence checker requires three distinct source roots and workdirs, exact A -> B -> C ancestry, generated changes on every lane, source-only handoff patches, adapter-appropriate shared/private output contracts, and successful framework commands. Go additionally proves exact reusable-byte accounting and cached B/C tests.

@forhappy
forhappy marked this pull request as ready for review August 11, 2026 10:53
@forhappy
forhappy merged commit c51b290 into main Aug 11, 2026
49 of 52 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant