feat(driver): validate and rename raw Workshop edits through workshop-rs - #454
Merged
Merged
Conversation
e54-bot
pushed a commit
that referenced
this pull request
Sep 30, 2026
… callees Review on #454 found two contract violations reachable through the agent surface. Value::Subroutine arguments (Start Rule callees) produced no reference, so a uniquely-named subroutine refused on reparse and a redeclared name could silently retarget a surviving binding; the index now records the call reference and resolves redeclared names to the last declaration, matching workshop-rs name binding. A deserialized EditTransaction also bypassed the constructor's invariants, so empty, overlapping, or unsorted edit lists could produce corrupted ok:true previews; validateTransaction re-normalizes the wire value. Edits that name a source outside the loaded input and renames to the symbol's own name now refuse instead of validating vacuously. Refs #434
11 tasks
Raw Workshop input now carries the advertised source-edit contract: validateEditTransaction applies the caller's transaction to the supplied current sources and reparses/revalidates the edited project through the session's own workshop-rs path, and semanticRename resolves a symbol (numeric id or declared name, as references/usage address them) or a source/line/col position and rewrites exactly the identifier spans the parsed program records — declarations, the Subroutine event binding, Call Subroutine callees, variable arguments, and Global.name/Event Player.name references. There is no textual-search fallback; unmapped occurrences refuse with rename-unmapped-span, same-namespace collisions with rename-name-collision, and edits that break the reparse with the real Workshop diagnostics. wright rename <NAME> <NEW_NAME> [INPUT] exposes the same validated rename: a source diff by default, an atomic write with --write that rechecks source identities and refuses edit-stale-source. Non-Workshop input stays at the provider boundary: the raw operations refuse with edit-requires-provider naming providerValidateEdit/providerSemanticRename, keeping provider-owned paths distinct. Closes #434
… callees Review on #454 found two contract violations reachable through the agent surface. Value::Subroutine arguments (Start Rule callees) produced no reference, so a uniquely-named subroutine refused on reparse and a redeclared name could silently retarget a surviving binding; the index now records the call reference and resolves redeclared names to the last declaration, matching workshop-rs name binding. A deserialized EditTransaction also bypassed the constructor's invariants, so empty, overlapping, or unsorted edit lists could produce corrupted ok:true previews; validateTransaction re-normalizes the wire value. Edits that name a source outside the loaded input and renames to the symbol's own name now refuse instead of validating vacuously. Refs #434
…on in cfg edges action_subroutine first-matched a CallSubroutine callee name, pointing the CFG edge at a shadowed declaration when two subroutines share a name; workshop-rs resolves redeclared names last-wins, and the semantic index now does too. Refs #434
main gained a subject parameter on run_configured and a RenderContext parameter on ResultPresentation::render_body in the inspect-presentation rework; pass the rename command no subject and render its body without the context. Refs #434
e54-bot
force-pushed
the
wright-434-validated-edits
branch
from
September 30, 2026 13:16
2c031b2 to
5ed643e
Compare
Teakowa
enabled auto-merge (squash)
September 30, 2026 13:17
Teakowa
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements #434: raw Workshop input now carries the advertised source-edit contract end to end.
validateEditTransactionapplies the caller's transaction to the supplied currentsourcesand reparses/revalidates the edited project through the session's ownworkshop-rspath. Malformed or invalid results refuse with the real parse/validation diagnostics and no partial preview; stale identities, unknown sources, overlaps, and invalid ranges keep their structured refusals.semanticRenameresolvestargeteither bysymbol— a numeric id or declared name, the same addressingreferences/usageuse — or by asource/line/colposition inside one identifier occurrence. Global variables, player variables, and subroutines rewrite through the exact identifier spansworkshop-rsrecords (Global.name/Event Player.nameprefixes preserved, comments and strings untouched). There is no textual-search fallback: unmapped occurrences refuserename-unmapped-span, same-namespace collisionsrename-name-collision, non-renameable kindsrename-unsupported-kind, and edits that break the reparse refuse with the parse diagnostic orrename-mismatch.wright rename <NAME> <NEW_NAME> [INPUT]exposes the validated rename on the CLI: a-/+diff preview by default, an atomic sibling-tempfile write with--writethat rechecks source identities (edit-stale-sourcewrites nothing).edit-requires-providernamingproviderValidateEdit/providerSemanticRename; unshipped kinds keepsource-provider-unavailable.RenameTargetgains the optionalsymbolfield (integer id or name); the existing position form stays valid. Operation names and response shapes are unchanged.wright-consumerexercises the new path (symbols→semanticRename) on Workshop fixtures.Docs updated:
docs/agent-contract.md,docs/cli/commands.md,docs/architecture/tooling.md.Closes #434
Test plan
cargo fmt --all -- --checkcargo clippy --workspace --all-targets --all-features -- -D warningscargo test --workspace --all-targets --all-features— all greengit diff --checkEvent Player.xprefix preserved), subroutine (declaration +Subroutinebinding +Call Subroutine); position and name/id addressing; stale-source and stale-write refusals; collision refusal; no partial previewsoverpy-cake.ws—cakePos→cakePositionproduces 18 exact identifier edits,Global.i2untouched,--writeresult reparses clean