fix(bundle): read TOML with @preventive/lockfile's parser - #183
Merged
Merged
Conversation
Adds @preventive/lockfile 1.0.0-alpha.1 and reads Cargo.toml, Cargo.lock and foundry.toml with its strict TOML parser (parseToml) in place of the reader loaders/toml.js carried since #179. The readers walk the parsed table tree: the dotted, inline and header spellings of a table are one table by construction. loaders/toml.js keeps readToml (the parser, with the file named in its errors), isTomlTable and the bracket helpers the Rust scanner shares. The parser refuses what those files are never written in, on top of what isn't TOML: local dates and times, a byte order mark, U+FFFD where a lenient decoder replaced bytes, a dotted key through a table a header made (Cargo's toml crate refuses it too). A foundry.toml profile's sub-tables are its values whichever way they are written, so a `no-collision` extends sees a `[profile.default.fuzz]` table as forge does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015nbp2vC4jLPbGN8cmorxAL
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
@preventive/lockfile1.0.0-alpha.1, the latest. main had no dependency on it; #172 pins 1.0.0-alpha.0.Cargo.toml,Cargo.lockandfoundry.tomlare now read with its strict TOML 1.0 parser,parseToml, instead of the readerloaders/toml.jshas carried since #179.What changes
stasis/package.json,pnpm-lock.yaml:@preventive/lockfilepinned exactly, like@preventive/upstream. It has no dependencies of its own.loaders/toml.js: 502 → 66 lines. It keeps:readToml(text, file):parseToml, with a TomlError's message prefixed by the file (crates/app/Cargo.toml: unterminated string at line 3). The error keeps its class andline, and the build still stops;isTomlTable, which tells a table from aTomlFloatorTomlDateTime;matchClose,splitTopLevel). They were never part of the TOML reader.parseCargoManifest,parseCargoLock,parseFoundryToml: these walk the parsed table tree instead of an entry stream, so the dotted, inline and header spellings of a table are one table by construction.DEP_KINDShas a null prototype, since its keys now come straight from the document.Behavior
The parser refuses everything the old reader refused, plus what these files are never written in:
tomlcrate refuses it too).Error messages follow the package:
<file>: <detail> at line N.One deliberate change in
foundry.toml: a profile's sub-tables are its values however they are written. So ano-collisionextends now sees a[profile.default.fuzz]table, as forge does. The old reader skipped header-spelled sub-tables, all exceptextends.main's handling of a dependency's
foundry.tomlit can't read (skipped with a warning) is unchanged here. #175 changes that separately.Verification
tests/toml.test.jsnow tests what the loaders rely on: the file-named error, the refusals above, and the tree's shapes (null-prototype tables, BigInt,TomlFloat,__proto__as a key). The parser's own tests live with the package.extendswritten as a table, and ano-collisionover afuzzsub-table.@preventive/lockfile, like the zero-dependency@exodus/stasis-core. The loaders import it when the bundle command loads.oxlintclean.#175 uses
tomlEntriesand will be rebased onto this once it lands.🤖 Generated with Claude Code
https://claude.ai/code/session_015nbp2vC4jLPbGN8cmorxAL
Generated by Claude Code