cli

Command-line interface for Radroots
git clone https://radroots.dev/git/cli.git
Log | Files | Refs | README | LICENSE

README (4541B)


      1 # Radroots CLI
      2 
      3 `radroots` is the local-first command-line host for the release-v1 Radroots
      4 crate graph. It consumes the canonical `radroots` facade and retains command
      5 parsing, client composition, output envelopes, and presentation concerns.
      6 
      7 The CLI is pre-release software. `Cargo.toml` pins the public Radroots library
      8 repository at an exact Git revision; `Cargo.lock` and
      9 `radroots.lib.source-lock.v1.toml` record the corresponding dependency graph
     10 and source evidence. The repository never falls back to a sibling checkout.
     11 
     12 ## Install and run
     13 
     14 Use the toolchain declared by `rust-toolchain.toml` and the committed lockfile:
     15 
     16 ```sh
     17 cargo build --locked
     18 cargo run --locked -- --help
     19 ```
     20 
     21 In an extbuild-enabled checkout, run `cargo extbuild doctor` first and route
     22 the commands through `cargo extbuild run -- ...`. A standalone checkout does
     23 not require an enclosing Radroots workspace or a local dependency override.
     24 
     25 ## Release-v1 command model
     26 
     27 Commands are organized by resource. Inspect any level with `--help`:
     28 
     29 ```sh
     30 radroots profile inspect --format json
     31 radroots health inspect --format json
     32 ```
     33 
     34 Only local profile and health inspection are executable in the initial crate
     35 release. The complete resource vocabulary remains parseable so automation gets
     36 a stable, structured `unsupported_operation` response while private predecessor
     37 runtimes are retired. No command silently falls back to a sibling checkout or
     38 legacy engine.
     39 
     40 Global controls include:
     41 
     42 - `--format terminal|json|ndjson` for stable output envelopes;
     43 - `--account-id` for an invocation-scoped account selection;
     44 - `--offline` or `--online` for explicit network policy;
     45 - `--dry-run` for validation without durable effects;
     46 - `--idempotency-key` and `--correlation-id` for mutation receipts;
     47 - `--no-input`, `--yes`, and `--approval-proof` for automation-safe approval;
     48 - `--quiet`, `--verbose`, and `--trace` for presentation detail.
     49 
     50 Machine consumers should prefer JSON for a single response and NDJSON for a
     51 stream. A nonzero exit is paired with the structured error in the output
     52 envelope; scripts should evaluate both.
     53 
     54 ## Configuration
     55 
     56 The current executable accepts only the command-line controls shown by
     57 `radroots --help`; it does not load `.env`, user, or workspace configuration.
     58 `profile inspect` and `health inspect` construct and close the pinned facade's
     59 local-only memory client. All write operations remain fail closed until their
     60 canonical SDK orchestration is implemented by a later release.
     61 
     62 `.env.example` is retained as pre-refactor implementation evidence, not as a
     63 description of active runtime behavior. Do not treat it as a supported
     64 configuration contract.
     65 
     66 ## Package migration
     67 
     68 The v1 crate migration removed compatibility namespaces and the CLI-owned
     69 generic signing, transport, storage, and sync engines. The initial CLI host
     70 uses only the final facade composition. `AGENTS.md` defines the current
     71 repository boundary and contribution rules; historical migration guidance is
     72 not a standalone build or release input.
     73 
     74 ## Verification
     75 
     76 The forge-agnostic standalone checks are:
     77 
     78 ```sh
     79 cargo fmt --all --check
     80 cargo check --all-targets --locked
     81 cargo test --all-targets --locked
     82 cargo clippy --all-targets --locked -- -D warnings
     83 RUSTDOCFLAGS="-D warnings" cargo doc --no-deps --locked
     84 scripts/verify-boundaries.sh
     85 scripts/verify-source-lock.sh
     86 scripts/verify-supply-chain.sh
     87 tools/verify-repository-boundary.sh
     88 ```
     89 
     90 The source-lock command checks the exact Cargo lock digest, public dependency
     91 revision, declared version and resolved shared package sources. It runs offline
     92 and rejects local overrides or mismatched inputs. The boundary command includes
     93 this check and byte-compares the root-only public API against its
     94 reviewed baseline and rejects forbidden repository roots or credential
     95 material. The supply-chain command validates the exact locked dependency
     96 graph, license policy, approved registries and immutable Lib source, then
     97 rejects forbidden capsule-local documentation and workflow roots. An
     98 extbuild-enabled checkout routes these commands through `cargo extbuild run --
     99 ...`.
    100 
    101 The standalone flake exposes exactly one real `radroots` package, check, and
    102 application for `aarch64-darwin` and `x86_64-linux`. It exposes no checkout
    103 wrapper, development shell, NixOS module, OCI artifact, or other system.
    104 
    105 ## Copyright and license
    106 
    107 Except as otherwise noted, all files in the `radroots_cli` distribution are
    108 Copyright © 2026 Tyson Lupul.
    109 
    110 This repository is licensed under GPL-3.0-or-later. See [`LICENSE`](LICENSE).