README (4541B)
1 # Radroots CLI 2 3 `radroots` is the local-first command-line host for the release-v1 Radroots 4 crate graph. It consumes the canonical `radroots` facade and retains command 5 parsing, client composition, output envelopes, and presentation concerns. 6 7 The CLI is pre-release software. `Cargo.toml` pins the public Radroots library 8 repository at an exact Git revision; `Cargo.lock` and 9 `radroots.lib.source-lock.v1.toml` record the corresponding dependency graph 10 and source evidence. The repository never falls back to a sibling checkout. 11 12 ## Install and run 13 14 Use the toolchain declared by `rust-toolchain.toml` and the committed lockfile: 15 16 ```sh 17 cargo build --locked 18 cargo run --locked -- --help 19 ``` 20 21 In an extbuild-enabled checkout, run `cargo extbuild doctor` first and route 22 the commands through `cargo extbuild run -- ...`. A standalone checkout does 23 not require an enclosing Radroots workspace or a local dependency override. 24 25 ## Release-v1 command model 26 27 Commands are organized by resource. Inspect any level with `--help`: 28 29 ```sh 30 radroots profile inspect --format json 31 radroots health inspect --format json 32 ``` 33 34 Only local profile and health inspection are executable in the initial crate 35 release. The complete resource vocabulary remains parseable so automation gets 36 a stable, structured `unsupported_operation` response while private predecessor 37 runtimes are retired. No command silently falls back to a sibling checkout or 38 legacy engine. 39 40 Global controls include: 41 42 - `--format terminal|json|ndjson` for stable output envelopes; 43 - `--account-id` for an invocation-scoped account selection; 44 - `--offline` or `--online` for explicit network policy; 45 - `--dry-run` for validation without durable effects; 46 - `--idempotency-key` and `--correlation-id` for mutation receipts; 47 - `--no-input`, `--yes`, and `--approval-proof` for automation-safe approval; 48 - `--quiet`, `--verbose`, and `--trace` for presentation detail. 49 50 Machine consumers should prefer JSON for a single response and NDJSON for a 51 stream. A nonzero exit is paired with the structured error in the output 52 envelope; scripts should evaluate both. 53 54 ## Configuration 55 56 The current executable accepts only the command-line controls shown by 57 `radroots --help`; it does not load `.env`, user, or workspace configuration. 58 `profile inspect` and `health inspect` construct and close the pinned facade's 59 local-only memory client. All write operations remain fail closed until their 60 canonical SDK orchestration is implemented by a later release. 61 62 `.env.example` is retained as pre-refactor implementation evidence, not as a 63 description of active runtime behavior. Do not treat it as a supported 64 configuration contract. 65 66 ## Package migration 67 68 The v1 crate migration removed compatibility namespaces and the CLI-owned 69 generic signing, transport, storage, and sync engines. The initial CLI host 70 uses only the final facade composition. `AGENTS.md` defines the current 71 repository boundary and contribution rules; historical migration guidance is 72 not a standalone build or release input. 73 74 ## Verification 75 76 The forge-agnostic standalone checks are: 77 78 ```sh 79 cargo fmt --all --check 80 cargo check --all-targets --locked 81 cargo test --all-targets --locked 82 cargo clippy --all-targets --locked -- -D warnings 83 RUSTDOCFLAGS="-D warnings" cargo doc --no-deps --locked 84 scripts/verify-boundaries.sh 85 scripts/verify-source-lock.sh 86 scripts/verify-supply-chain.sh 87 tools/verify-repository-boundary.sh 88 ``` 89 90 The source-lock command checks the exact Cargo lock digest, public dependency 91 revision, declared version and resolved shared package sources. It runs offline 92 and rejects local overrides or mismatched inputs. The boundary command includes 93 this check and byte-compares the root-only public API against its 94 reviewed baseline and rejects forbidden repository roots or credential 95 material. The supply-chain command validates the exact locked dependency 96 graph, license policy, approved registries and immutable Lib source, then 97 rejects forbidden capsule-local documentation and workflow roots. An 98 extbuild-enabled checkout routes these commands through `cargo extbuild run -- 99 ...`. 100 101 The standalone flake exposes exactly one real `radroots` package, check, and 102 application for `aarch64-darwin` and `x86_64-linux`. It exposes no checkout 103 wrapper, development shell, NixOS module, OCI artifact, or other system. 104 105 ## Copyright and license 106 107 Except as otherwise noted, all files in the `radroots_cli` distribution are 108 Copyright © 2026 Tyson Lupul. 109 110 This repository is licensed under GPL-3.0-or-later. See [`LICENSE`](LICENSE).