commit 914d98f6703047d5077535afa835e4f348ad834d parent 1898576a18435d4f455ba70555ef0469d6c06436 Author: triesap <tyson@radroots.org> Date: Mon, 27 Jul 2026 08:12:18 +0000 workspace: verify independent cargo lock - Preserve the standalone lib lockfile and release boundary. - Record the exact checksum and repeated locked metadata result. - Prohibit cross-repository lockfile unification under the approved topology. - Require extbuild-routed zero-diff validation for future graph changes. Diffstat:
| A | docs/implementation/DEPENDENCY_RESOLUTION.md | | | 14 | ++++++++++++++ |
1 file changed, 14 insertions(+), 0 deletions(-)
diff --git a/docs/implementation/DEPENDENCY_RESOLUTION.md b/docs/implementation/DEPENDENCY_RESOLUTION.md @@ -0,0 +1,14 @@ +# Dependency resolution + +This standalone repository owns its `Cargo.lock`. Under `RCRV1-DEV-001`, the +release-v1 refactor does not combine it with the SDK lockfile or make either +repository depend on the other's workspace state. + +Step 017 verified the current lock checksum as +`4462008577c9b46a97a01acce7efd34c95e98e46bc54468cb278f066f7943726`. +Repeated `cargo metadata --locked --no-deps --format-version 1` and the full +repository contract lane leave it unchanged. + +Dependency changes must use repository-owned extbuild commands, preserve +`--locked` zero-diff validation, and update this evidence when the resolved +graph intentionally changes.