Release evaluation — Twig 3.1

The initial review covered Rust f6718af (3.0.0) and Python reference cce3235. It found data-integrity, resource-use, compatibility, installer, and release gaps despite the existing suite passing. This page tracks the implementation work for 3.1.0 on 2026-10-05, rather than leaving resolved issues labeled as open.

Audit resolution

FindingResolutionRegression evidence
Stale source cachesSnapshot + SHA-256 content key; validate completed schema and SQLite integrityChanged/deleted input and corrupt-cache tests
Partial caches accepted after failurePrivate staging; publish only completed immutable databasesFailed trailing JSON, cancellation, concurrent builders
Mixed arrays reorderedRank every scalar/container in source orderExact reconstructed mixed-array equality
Large unsigned integers become stringsRestore signed or unsigned integer valuesu64::MAX and i64::MIN round trips
Unicode rendering panicsGrapheme/display-width truncation; byte-stable ASCII folding for highlightsEmoji, CJK, dotted-I and tiny-terminal rendering
Path collisions / hidden JSON rootsJSON-quoted bracket paths, unique path index, single-root validationSpecial keys, duplicate keys, trailing documents
Whole-tree JSON allocationSerde node visitor with 1,024-node insertion batchesLarge-file benchmark with time/RSS budgets
All siblings allocated/rendered256-row pages; deepest-column viewport; bounded inspector preview1,000-item traversal, page-crossing jumps
Unused FTS index and wildcard surprisesRemove unused FTS; literal substring search in source order%_ literal and numeric array-order tests
CLI flag and output inconsistenciesComposable fix/print, conflicting check rejected, shared output path, consistent JSON indentationReal executable stdout/file/status tests
YAML case/multi-document differencesShared extension detection; stream-aware print modeUppercase extension and document-stream tests
Silent truncated copyingComplete subtree export or explicit size errorExport depth/size contract; preview/export separation
UI lifecycle gapsPanic-safe terminal guard, worker cancellation/join, disconnect errors, synchronized focus and propagated draw errorsInjected-config tests and render/interaction regressions
Scalar roots and missing controlsSelectable root, mouse controls, Vim movement and first/last keysScalar, navigation and key-event coverage
Clipboard handle lifetimeRetain handle while application runsHost-dependent persistence remains a manual check
Real-profile test side effectsTemporary loader/config injection; remove ignored theme test and leaked test directoriesEntire suite runs inside workspace sandbox
Plaintext cache lifecycle undocumentedPrivate Unix permissions, retention, clear/no-cache modes and explicit docsEphemeral and cache contract tests
macOS config migration missingImport legacy config only when new config is absentExplicit source contract; existing-config precedence
Broken auto-release dispatchAuthenticated token, required permission, retry existing unpublished tag after successful CIWorkflow review and hosted CI/release run
Wrong-ref release binariesResolve and validate tag/commit before verification/build jobsTag input validation and immutable checkout
Installer failuresBash help, checksum fallback/fail-closed policy, release pinning, destination handling, cleanup and atomic installOffline installer contract suite
Unsupported declared Rust minimumSet 1.88 and test it alongside stable on three OSesLocal minimum-version tests and CI matrix
Unsound/unmaintained YAML dependenciesReplace serde_yml/libyml with serde_norwayRustSec audit and YAML regression suite
Website/source driftRewrite website in main repo; generate guides and installer from canonical filesStatic link/anchor checks and browser QA

The YAML dependency decision follows RustSec's serde_yml advisory and the serde_norway project. Clipboard image support is disabled because Twig only copies text, reducing unnecessary dependencies. CI also checks licenses, advisory status, and dependency sources.

Verification commands

cargo fmt --all -- --check
cargo clippy --locked --all-targets -- -D warnings
cargo test --locked --all-targets
cargo test --locked --doc
cargo +1.88.0 test --locked --all-targets
cargo audit --deny warnings
shellcheck install.sh
python3 scripts/test_installer.py
python3 scripts/build_site.py
python3 scripts/check_site.py
cargo build --release --locked
python3 scripts/benchmark.py --binary target/release/twig

The release workflow is the authoritative record of platform results. Tests run without real user caches/config or a live clipboard. The benchmark's Linux CI budget is 120 seconds and 512 MiB for 90,000 deterministic items; this is a regression ceiling, not a speed guarantee or a comparison against Python.

Local verification results

On macOS, Rust 1.88.0 and the current installed toolchain passed 90 unit, integration, and regression tests with none ignored; the documentation test also passed. Formatting, Clippy, seven installer contract tests, site link checks, and the dependency audit passed. The audit reported no advisories or warnings. Browser checks covered desktop/mobile layouts, sample navigation, installation tabs, copying, and guide links.

A release build ingested the deterministic 42,378,891-byte JSON fixture (900,001 nodes) in 12.24 seconds with 179.92 MiB peak RSS on the development Mac. These are local observations, not cross-platform performance guarantees. Hosted CI and release logs provide the platform-specific verification record.

Deliberate limits and external requirements

These limits are documented in the user guide instead of being hidden behind claims of universal static binaries, constant memory, or complete Python parity.