ArkGate
4.8.24

Published

Slices follow-ups. Audit fixes. Less memory.

ArkGate 4.8.24 is published. Current is 4.8.25. Follow-ups to the 4.8.23 hierarchical slices (#335–#338), every defect a full product audit confirmed (#339), and much lower memory per validation. No required config migration: a config that loads in 4.8.23 still loads. That is Contener · Guiar · Ordenar.

Upgrade

Install 4.8.24

npm install -D arkgate@4.8.24
npx arkgate upgrade --json
npx arkgate-check --doctor

Current is 4.8.25 on npm latest. Install that unless you need this patch pinned. No schema bump. Ids that changed meaning warn (CONFIG_CHILD_SLICES_INERT, CONFIG_SLICE_LEGACY_STARS_ID) and keep their 4.8.23 verdict for one release.

Minimum version 4.8.24 for the new config fields (sharedImportsSlice object form with stopAt, childSlices.message, childSlices.siblings.ratchet). arkgate 4.8.23 and older reject them at config load. Pin 4.8.24 in the write hook and CI first.

What shipped

The slice walls, finished. The gate, audited.

Composition roots: stopAt (#335)

sharedImportsSlice accepts { "mode": "deny-cross-parent", "stopAt": [...] }. The CROSS_PARENT_VIA_SHARED walk never passes through a declared composition root. Findings carry via. The string forms are unchanged.

Advisory on day 1 (#336)

Advisory sibling crossings stay warnings. The anti-growth ratchet arms per rule only when the baseline already records one. Optional childSlices.siblings.ratchet: true always fails a new crossing, false only measures.

Inner-wall text: childSlices.message (#337)

Sets the text for CROSS_SIBLING_SLICE findings. The universe-wall message is never reused. Same text in ark-check, CI, the write hook, MCP, and ESLint.

Version warnings need evidence (#338)

New-key version warnings fire only when the repo pins an older arkgate (package.json, installed copy, lockfile, hook script, or CI workflow), and point at that file and line.

Full product audit (#339)

110 reproduced defects fixed across the CLI, write hook, MCP, ESLint, ArkRules, ArkRun, ArkOrder and packaging. --changed / --local no longer give a false green; MCP tools no longer disappear; the MCP Registry entry now starts the server.

Less memory, same verdicts

On a 20k-file repo, ark-check full went from 422 MB / 3.7 s to 303 MB / 2.3 s; the ApplyPatch hook from 649 MB to 414 MB. Verdicts are byte-identical.

Behavior changes

Read these before you upgrade.

  • sliceIdentity: "stars" keeps every star binding (modules/*/api/* binds orders/api/v1, not api/v1). Legacy 4.8.23 ids keep loading and keep their verdict for this release, with CONFIG_SLICE_LEGACY_STARS_ID naming the new id. The legacy form is removed in the next minor.
  • ArkOrder apply() only accepts a proposal bound to the current Release (ARKORDER_STALE_PROPOSAL), so proposals serialized under 4.8.23 are refused.
  • The write hook fails closed: if it cannot run inside an Ark project, governed writes are denied with exit 2 (WRITE_GATE_UNAVAILABLE) instead of exit 1.
  • childSlices without peerIsolation: true and allowed: false still loads but is inert and warns. commonFolders counts only folders directly under the universe. An enforced invariant with no evidence is uncovered. --update-baseline refuses --changed / --local.

Honesty

What stayed the same.

No schemaVersion bump. Does not close K01 or Z09. Import rules still hold at write and at merge. Required CI is still the hard line. ArkOrder stays opt-in.

Maintainer source: CHANGELOG.md ↗