Ship the Runtime
Shipping Harmos means proving the same contracts under the feature set the consumer application will actually compile.
Choose Features Explicitly
Section titled “Choose Features Explicitly”The base crate enables no artifact runtime by default:
harmos = { version = "0.2" }harmos = { version = "0.2", features = ["sidecar"] }harmos = { version = "0.2", features = ["guest"] }Do not enable both unless the application installs both kinds.
Validate
Section titled “Validate”mise run checkmise run test:defaultmise run test:rustmise run test:examplesmise run build:rustdoc:releasemise run build:docs:releasemise run check formats, lints with warnings denied, and checks every target.
test:default proves the empty default feature set. test:rust exercises all
features. The example task executes the normal application, direct guest, and direct
sidecar paths.
Measure Boundaries
Section titled “Measure Boundaries”Performance tasks are recorded measurements rather than timing gates:
mise run bench:streamsmise run bench:sidecarmise run bench:seriesmise run bench:sim:determinismThe sidecar measurement reports sample count, protobuf payload MiB/s, latency, and sequence gaps across the gRPC batching path.
Artifact Installation
Section titled “Artifact Installation”Ship one executable for a sidecar and one component .wasm for a guest. Before
activation:
- Verify file provenance and integrity using the application's installation policy.
- Read the embedded declaration without executing the artifact.
- Resolve all declarations through
harmos::load::Plan. - Activate in dependency-first order.
Static metadata prevents discovery from requiring execution. It does not make native code safe; run sidecars under OS policy appropriate to the application.
Recovery
Section titled “Recovery”Always test a second boot with artifact files absent. Application history and state must recover through application catalogs alone. Artifact unavailability may remove future functionality, but it must never make past accepted application changes unreadable.