Skip to content
Merged
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
72 changes: 72 additions & 0 deletions docs/EXAMPLES.md
Original file line number Diff line number Diff line change
Expand Up @@ -180,6 +180,78 @@ repomin . \
Only direct entries in `[packages]`, `[dev-packages]`, and `[requires]` are
eligible. Pipenv source settings and `Pipfile.lock` are preserved.

## Shrink a Node package manifest without Node

The Node manifest reducer is a structural `package.json` shrinker. It does not
need a Node runtime, package install, registry access, lifecycle scripts, or
external network: the oracle in the fixture is plain Python. The repository
ships a network-free fixture under `benchmarks/node-package/` that exercises
this path end to end. See the [fixture notes](../benchmarks/node-package/README.md)
for the original layout and the [host-backend boundary](../SECURITY.md) before
running anything else through it.

Create a temporary output parent outside the fixture and run the reduction
from the repository root:

```sh
out_parent="$(mktemp -d /tmp/repomin-node-package.XXXXXX)"
PYTHONPATH=src python3 -m repomin benchmarks/node-package \
--command 'python3 reproduce.py' \
--match 'ORIGINAL_FAILURE' \
--adapter node \
--source-reducer none \
--output "$out_parent/result"
```

The reducer keeps exactly two files in the exported payload:

```text
package.json
reproduce.py
```

Inside `package.json` the required entries are preserved: the `required-sdk`
runtime dependency pinned to `1.0.0` and the `packages/required` workspace
entry. The removable manifest noise that the reducer drops includes the
`unused-sdk` dependency, the `unused-test-tool` dev dependency, the unused
`unused` script, the unused workspace entry, and the `unused-transitive`
override. The `engines` block is not consulted by this adapter and is
removable in principle; treat any exact file shape in the minimized payload
as informational rather than a contract.

Validate the sidecar report and the exported payload fingerprint without
rerunning the failure command:

```sh
PYTHONPATH=src python3 -m repomin report validate \
"$out_parent/result.repomin/report.json" \
--payload "$out_parent/result" --json
```

The validator reports `valid: true`, `payload_checked: true`, and
`payload_fingerprint_verified: true` with `payload_fingerprint_mode: "exact"`,
which means the report's recorded tree fingerprint matches the exported
payload byte-for-byte under the `tree-sha256-v2` policy.

Run the configured oracle independently from the exported payload to confirm
the reduction still fails for the same reason:

```sh
( cd "$out_parent/result" && python3 reproduce.py )
```

The command exits with status `1` and prints `ORIGINAL_FAILURE` on stderr.
That marker is emitted by the fixture's Python oracle only when
`required-sdk` is still pinned to `1.0.0` and `packages/required` is still
listed in `workspaces`, so the exit status and marker together cover the
required/workspace contract without depending on npm.

This workflow is adapter evidence for the configured Python oracle, not a
guarantee that an arbitrary minimized `package.json` installs, builds, or
runs as an npm application. To assert anything about a real npm project, you
still need a Node toolchain and a real `npm install` plus lifecycle
verification, both of which are outside this fixture by design.

## Shrink a Cargo workspace without network access

The repository includes a local-only Rust workspace with one required path
Expand Down