1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103 | {;; Exact pins — the Closure compiler version rides on these two, and the
;; committed dist/ must rebuild byte-identical (deploy/check-dist.sh). Same
;; known-good pair as the rest of the suite's CLJS repos.
;;
;; Relative paths only — never :local/root, never an absolute path: the idpat
;; publish gate scans every decompressed git object for local path fragments.
;;
;; THE RULE: our OWN kits are ClojureScript libraries and are consumed as
;; SOURCE off this classpath — one compiled copy per build, one cljs.core, one
;; `Identity` class in the build. Foreign JS/native packages (@orbitdb/core,
;; the libp2p family, helia, ws, node:*) stay string requires: that is ordinary
;; interop, not the hybrid. ardegazu-id-kit is still reached through its npm
;; install, so the sha pin in package.json remains the ONE cross-repo
;; dependency mechanism (dev/docs/CLJS.md); this path only points the compiler
;; at what that pin unpacked, and this file needs no second pin.
;;
;; The comment that used to sit here argued the opposite — that id-kit had to
;; stay a dist import because this kit RE-EXPORTS `Identity`, and compiling
;; id-kit in here would make that a different class object from
;; `ardegazu-id-kit`'s. That was true only of the MIXED regime it described,
;; and it is now false in both directions:
;; - Nothing in the suite does `instanceof` against id-kit's Identity. Every
;; consumer duck-types it (`.fromSeed`, `.signRaw`, `.assert`,
;; `.publicKeyB64`, `.fingerprint`), and id-kit attaches that whole surface
;; with STRING names precisely so :advanced cannot rename it — which is
;; what makes a source-compiled class and a dist-compiled one
;; interchangeable across the boundary rather than dangerous.
;; - Keeping the dist import is what MANUFACTURED a second copy, now that
;; every other kit compiles id-kit from source: the bot's worker would hold
;; rooms-kit's dist-imported id-kit while its own graph compiled another.
;; Our `Identity` is therefore ardegazu.id.identity/Identity, compiled here.
;; Same seed in, same publicKeyB64 out, same signatures on the wire — the
;; interop that matters is cryptographic, not object identity, and
;; test/api.test.mjs now proves exactly that against the installed id-kit dist.
;;
;; No new npm dependency comes with this: ardegazu.id.{identity,crypto} are
;; pure WebCrypto + base64 and require nothing outside the suite. @noble/curves
;; lives only in ardegazu.id.xkey, which this kit does not use.
;;
;; PROMESA IS DELIBERATELY ABSENT, and this is the note that says so before
;; someone adds it to match chat. dev/docs/CLJS.md names `p/let` as the suite's
;; one async idiom; it was measured here and rejected for three reasons that
;; are all specific to this kit, not to the idiom:
;;
;; 1. SIZE. chat pays ~1.8 KB gz because it builds :advanced and Closure DCEs
;; everything promesa.core does not reach. This build is :simple (see
;; shadow-cljs.edn — :simple removes the externs-inference risk class, and
;; almost every line here is interop with untyped ESM). Nothing is DCE'd, so
;; one `p/let` in one function measured at +115,703 bytes raw / +12,272 gz
;; on dist/shared.js: +10.4% raw, +8.2% gz, for the whole runtime.
;; 2. MICROTASK HOPS. promesa's ClojureScript runtime is NOT js/Promise — it
;; ships promesa/impl/promise.js and schedules each link through its own
;; nextTick. This kit's recorded transcripts settle with a FIXED number of
;; microtask turns (`tickMicro(8)` in test/helpers/fakes.mjs), so a chain
;; with a different hop count moves a golden vector — and the vectors are
;; the cross-implementation proof against the retired TypeScript. They may
;; be added to, never regenerated.
;; 3. THE LIBRARY BOUNDARY. Every promise this kit returns crosses into a
;; consumer (the bot, its per-room workers, @orbitdb/core callbacks). A
;; `p/let` result is thenable but not `instanceof Promise`, and an
;; unhandled rejection on one does not reach the global handler. chat owns
;; both ends of its chains; a kit does not.
;;
;; What replaces it: `later` / `attempt` / `each-in-order!` / `every-in-order!`
;; in ardegazu.rooms.js, four native-promise combinators that name the four
;; chain shapes this tree actually repeats. Flattening came from decomposition
;; instead — lib/log's `open` and lib/net's `start` are the two that needed it.
:paths ["src" "node_modules/ardegazu-id-kit/src"]
:deps {org.clojure/clojurescript {:mvn/version "1.12.134"}
thheller/shadow-cljs {:mvn/version "3.3.6"}}
:aliases
{:dev {:extra-deps {cider/cider-nrepl {:mvn/version "0.59.0"}}}
;; cljfmt is a TOOL, not a dependency. :replace-deps keeps it off the build
;; classpath (neither shadow-cljs nor clojurescript is loaded to run it) and
;; :replace-paths keeps the sources off it too — cljfmt only ever reads the
;; files named on the command line. Exact pin, same rule as the two above.
;; The config is committed beside this file; both paths are relative, because
;; the idpat publish gate aborts on a local filesystem path in any object.
;; Wired into `npm test` as the FIRST link of the test script itself, not as
;; a `pretest` hook: an npm lifecycle hook is skipped outright under
;; `ignore-scripts=true`, which is a gate that passes by not running.
:cljfmt {:replace-deps {dev.weavejester/cljfmt {:mvn/version "0.13.1"}}
:replace-paths []
:main-opts ["-m" "cljfmt.main" "--config" ".cljfmt.edn"]}
;; clj-kondo is a TOOL too, same shape and same reasons as :cljfmt above:
;; :replace-deps keeps it off the build classpath and :replace-paths keeps the
;; sources off its own, since it reads only the paths named on the command
;; line. Running it as a pinned JVM dep rather than the native binary is
;; deliberate — the gate must not depend on what happens to be installed, and
;; three versions (2025.06.05, 2026.01.19 and this pin) were measured to give
;; identical findings on this tree, as did the native binary.
;; Config and the defclass hook are committed at .clj-kondo/ beside this file;
;; every path here is relative, because the idpat publish gate aborts on a
;; local filesystem path in any object.
;; Wired into `npm test` as the second link of the test script itself, right
;; after cljfmt and before anything compiles — never as a `pretest` hook, which
;; `ignore-scripts=true` skips outright (a gate that passes by not running).
;; --fail-level warning is the default and is what makes this a gate; the
;; config promotes the one :info linter this tree can trip so it cannot print
;; a finding and still exit 0.
:clj-kondo {:replace-deps {clj-kondo/clj-kondo {:mvn/version "2026.08.04"}}
:replace-paths []
:main-opts ["-m" "clj-kondo.main" "--lint" "src" "--fail-level" "warning"]}}}
|