Skip to content

feat(graph): resolve full dependency graph directly from .zpkg.toml - #530

Merged
ORESoftware merged 8 commits into
mainfrom
ai/fast-manifest-dependency-graph
Oct 3, 2026
Merged

ORESoftware merged 8 commits into
mainfrom
ai/fast-manifest-dependency-graph

Conversation

@ORESoftware

@ORESoftware ORESoftware commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

What changed

Adds zed graph local as a read-only prospective resolver for a local .zpkg.toml, aimed at AI/tooling that needs the whole selected dependency graph before install or lockfile mutation.

Fast path

  • recursively resolves exact versions using immutable registry view=declared graph metadata instead of downloading/extracting every package artifact just to inspect its manifest
  • keeps package/version/declared-graph metadata cached in-process during resolution
  • emits compact deterministic JSON by default, with sorted/deduplicated nodes and edges and a stable semantic analysis_digest
  • includes runtime + build dependencies by default; --runtime-only projects runtime edges
  • honors workspace members and [overrides.path]
  • intentionally ignores the ambient machine-wide local registry so automation does not silently depend on unrelated registered checkouts

Hardening

  • separates semantic unsatisfiability from operational failures, so auth/network/corrupt-metadata errors are never reinterpreted as reasons to backtrack to an older version
  • verifies canonical zpkg/dependency-graph/v1 JSON plus semantic digest and validates a present digest response header
  • verifies package/version identity against registry metadata
  • HTTPS required outside loopback; redirects disabled; metadata requests bounded to 30 seconds
  • 32 MiB per-document ceiling, 10k active-coordinate ceiling, 256 provenance-depth ceiling, plus shared 50k-node/500k-edge bounds
  • rejects cross-registry edges instead of resolving them against the wrong registry
  • artifact-manifest fallback is explicit (--allow-artifact-fallback) and visible in output stats
  • output files are atomic and no-clobber

Contract/output

The prospective output intentionally uses zpkg/local-dependency-graph/v1 rather than pretending to be an authoritative resolved graph. Pre-lock analysis does not yet have the registry-snapshot + lock provenance required by the canonical resolved zpkg/dependency-graph/v1 contract.

Tests/docs

Adds solver tests for diamond deduplication, backtracking, cycles, and the operational-error/backtracking boundary; extends the flags2env contract tests for the new command; adds docs/dependency-graph-cli.md with AI/tooling usage and safety semantics.

Audit finding behind the change

Existing zed tree --json is lock/materialization-oriented, while install resolution discovers transitive dependencies through package artifacts. The registry/interface layer already exposes immutable declared graph metadata specifically suited to a local resolver, so this PR adds that missing analysis path without changing zed graph package byte-preserving behavior.

CI status

Exact-head policy/contract checks including agents policy, formal review procedure, flags2env forward compatibility, and the package-graph contract validation reach their expected validation stages. Rust build/test jobs are currently blocked before rustc by the repository's committed Cargo.lock being out of sync with Cargo.toml: cargo check --locked --all-targets exits with cannot update the lock file ... because --locked was passed. This is present at the base revision as well; this PR does not weaken --locked or modify the lockfile blindly. A temporary branch-only diagnostic workflow was removed and is not part of the final diff.

@ORESoftware
ORESoftware merged commit 388161f into main Oct 3, 2026
17 of 47 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant