Skip to content

Infer the web layer and enforce native-only builds end to end - #107

Merged
ctate merged 5 commits into
mainfrom
feat/native-only-host-a
Jul 11, 2026
Merged

ctate merged 5 commits into
mainfrom
feat/native-only-host-a

Conversation

@ctate

@ctate ctate commented Jul 10, 2026

Copy link
Copy Markdown
Collaborator

Why

Canvas apps carried the whole webview layer for nothing: WebView2 machinery and a staged WebView2Loader.dll on Windows, frontend staging paths, and JS bridge dispatch — with no way to build a lean, honestly native-only binary. Community request (#84 framed it as host = "native"); this lands the inference-first version so most apps get it with no declaration at all.

What

  • Inference: the build graph parses app.zon — an app keeps the web layer iff it declares web use (a frontend block, the "webview" capability, a shell webview view, or the chromium engine). Otherwise the Windows host compiles its stub layer, the loader is neither installed nor staged, dev PATH wiring is skipped, and packages ship lighter (~236 KB per Windows app)
  • Override: .webview_layer = "auto" | "include" | "exclude" in the manifest (and -Dweb-layer), default auto
  • Enforcement: contradictory manifests (exclude + web declarations) are rejected with one consistent teaching message at native validate, build configure, runner compile, and package time; a native-only build that reaches webview creation at runtime fails fast with WebViewLayerNotBuilt and the exact line to add — never a blank window
  • Audits: a PE cross-audit build step asserts native-only Windows exes never reference the loader while webview apps must; native check and the package report print the web-layer verdict (web layer: none (inferred))
  • Null-platform gate tests cover every runtime path; the vendor-pin CI check pins the new conditional wiring

Notes

  • macOS/Linux binary size is unchanged in this round — their compile seams are the follow-up; this round is inference, Windows, packaging, and the enforcement contract
  • The Wine CI smokes now exercise the stub host path

Verification

Full suite, validate, examples battery, all seven smokes, PE audit both directions, and live checks of every enforcement boundary green.

- The build graph parses app.zon and strips the Windows webview layer, loader staging, and dev PATH wiring when nothing declares web use; a webview_layer manifest field and -Dweb-layer flag override inference in both directions
- Conflicting declarations are rejected with one teaching message at validate, configure, runner compile, and package time, and a native-only build that reaches webview creation fails fast with WebViewLayerNotBuilt instead of a blank window
- A PE cross-audit build step pins that native-only Windows exes never reference the loader while webview apps must, and native check prints the web-layer verdict

Co-authored-by: WhiteHades <44260523+WhiteHades@users.noreply.github.com>
@vercel

vercel Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
native-sdk Ready Ready Preview, Comment Jul 11, 2026 3:57pm

- app_manifest.web_layer owns the declaration scan, engine folding, and include/exclude decision, usable at comptime by the runner and at runtime by the build graph, validator, CLI, and generated scaffolds, with boundary ownership documented where each adapter lives
- Packaging decides from the resolved engine so --web-engine overrides cannot skew the layer, the runner guard covers shell views and manifest chromium, and the full scaffold emits the same inference, conflict panic, and conditional Windows wiring as the SDK graph
- A contract matrix test runs every manifest shape through every boundary form so the definitions can never diverge again
- The capabilities page counts a Chromium-resolved engine as web intent and points at the override; the app.zon reference gains the webview_layer field, its inference and include/exclude semantics, and the exclude-conflict rule with the shipped error's remedy
- Both build graphs forward their computed web-layer decision to native package via a new --web-layer flag, so the exe and the package can never disagree; a confirming flag keeps the manifest's reason while an overriding one names itself
- Packaging PE-scans Windows binaries and refuses to package a loader-referencing exe under a loaderless decision, closing the mismatch for hand-built binaries too
- Fixes an adjacent buildgraph bug where a sentinel-terminated path allocation was returned as a plain slice
- NATIVE_SDK_ALLOW_WEBVIEW2_STUB now excludes the embedded layer even when WebView2 headers are globally visible, so a native-only build can never reintroduce the loader reference; the vendor pins lock the guard order
- The stub message says the layer is excluded by configuration instead of claiming the header is missing
@ctate
ctate merged commit 9b4f62d into main Jul 11, 2026
21 checks passed
ctate added a commit that referenced this pull request Jul 11, 2026
- Bump the CLI, platform packages, and runtime version to 0.4.4.

- Fold the v0.4.4 release notes for #105, #106, #107, and #110 into the marked changelog entry.

- Credit co-authors in the v0.4.4 release notes and repair the v0.4.3 contributor list.
@ctate ctate mentioned this pull request Jul 11, 2026
ctate added a commit that referenced this pull request Jul 11, 2026
- Bump the CLI, platform packages, and runtime version to 0.4.4.

- Fold the v0.4.4 release notes for #105, #106, #107, and #110 into the marked changelog entry.

- Credit co-authors in the v0.4.4 release notes and repair the v0.4.3 contributor list.

This branch was successfully deployed

1 active deployment
Preview — ad737083 Deployed Jul 11, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant