Skip to main content

dev_prune/
constants.rs

1// Copyright 2026 VKrishna04
2// SPDX-License-Identifier: Apache-2.0
3
4// Centralized application constants and default configurations.
5//
6// Serves as the single source of truth for app metadata, versioning,
7// default thresholds, and file paths.
8
9/// Application crate version derived dynamically from `Cargo.toml`.
10pub const VERSION: &str = env!("CARGO_PKG_VERSION");
11
12/// Minimum supported Rust version, derived dynamically from `rust-version` in
13/// `Cargo.toml` — which is the single source of truth for the MSRV. Only `cargo
14/// install` users ever meet it; every other channel ships a prebuilt binary.
15pub const MSRV: &str = env!("CARGO_PKG_RUST_VERSION");
16
17/// Application name.
18pub const APP_NAME: &str = "dev-prune";
19
20/// Author of dev-prune.
21pub const AUTHOR: &str = "VKrishna04";
22
23/// Canonical source repository.
24///
25/// The one in `Cargo.toml` is only visible to people who already found the crate. This
26/// one is compiled into the binary, so a copy of the executable still says where it came
27/// from.
28pub const REPO_URL: &str = "https://github.com/Life-Experimentalist/dev-prune";
29
30/// Project homepage.
31pub const HOMEPAGE_URL: &str = "https://devprune.vkrishna04.me";
32
33/// The one-line credit printed under interactive output.
34///
35/// Deliberately plain text in plain sight: it is not obfuscated, not assembled at
36/// runtime, and not checked anywhere. Anyone may fork this project and change this line
37/// — the Apache-2.0 licence says so, and nothing in the code argues. It exists so that
38/// the common case, someone running the published binary, shows where it came from.
39pub const ATTRIBUTION_LINE: &str =
40    "dev-prune · made with ♥ by VKrishna04 · github.com/Life-Experimentalist/dev-prune";
41
42/// What the banner says the tool is, in one line.
43///
44/// The framing people arrive with is "the `node_modules` cleaner". That was fair when
45/// there were four adapters and has been wrong for a long time — and the banner is the
46/// first screen of every interactive command, so it is the cheapest place to correct it.
47/// No count of package managers here on purpose: a number in a banner is a number that
48/// goes stale the next time an adapter lands.
49pub const TAGLINE: &str = "Every dependency directory on this machine, in one command.";
50
51/// The half of the pitch that is a promise rather than a description.
52///
53/// It sits under [`TAGLINE`] because "deletes directories" is the part a new user is
54/// right to be nervous about, and the answer to it should not be three screens away in
55/// the README. Both halves of the sentence are load-bearing: the lockfile rule is what
56/// the engine actually enforces, and `undo` is what covers the case where the rule was
57/// satisfied and the user still wanted the directory back.
58pub const TAGLINE_SAFETY: &str =
59    "Only what a lockfile can rebuild — and `devp undo` puts back the last run.";
60
61/// The licence sentence under the declaration, in both wizard paths.
62///
63/// Apache-2.0 needs no click-through and this is not one: the licence governs use
64/// whether or not anybody reads this line. It is here because the screen it sits on is
65/// the first thing a new user meets, and a tool that deletes directories should say what
66/// it does and does not promise at that moment rather than in a file called LICENSE.md.
67/// Sections 7 and 8 are named so the disclaimer can be checked rather than taken on
68/// trust.
69pub const LICENCE_NOTICE: &str =
70    "Apache-2.0 sections 7-8: no warranty, no liability. Using it accepts that.";
71
72/// The body of `devp --version`.
73///
74/// Built at runtime rather than with `concat!`, which only takes literals and would mean
75/// spelling the author and the URL a second time. Two copies of a string are two things
76/// that can disagree, and this one exists precisely so that a stray copy of the binary
77/// can still be traced back.
78pub static LONG_VERSION: std::sync::LazyLock<String> = std::sync::LazyLock::new(|| {
79    format!(
80        "{VERSION}\n\
81         author:     {AUTHOR}\n\
82         repository: {REPO_URL}\n\
83         homepage:   {HOMEPAGE_URL}\n\
84         license:    Apache-2.0"
85    )
86});
87
88/// How many prune passes `devp stats` keeps a summary of.
89///
90/// The registry is rewritten in full on every save, so this list is a file-size decision
91/// as much as a display one. Fifty passes is roughly a year of a fortnightly schedule.
92pub const PRUNE_HISTORY_LIMIT: usize = 50;
93
94/// How many restore measurements one adapter's throughput average is worth.
95///
96/// Past this, the running totals are halved before the new sample is added, so the
97/// average follows the machine rather than remembering a disk it no longer has. A plain
98/// lifetime mean would quote a spinning-rust number years after the SSD went in.
99pub const RESTORE_RATE_SAMPLE_CAP: u32 = 20;
100
101/// The shortest restore worth learning a throughput from, in milliseconds.
102///
103/// A restore that returned in under this is a manager deciding it had nothing to do —
104/// the packages were still in its cache, or already on disk. Averaging those in would
105/// claim a rate no cold restore can reach.
106pub const RESTORE_RATE_MIN_MILLIS: u64 = 250;
107
108/// The release that started recording per-repository totals and the pass history.
109///
110/// A machine that pruned for months on 1.0.0 has a large lifetime total and no history at
111/// all, and reading that as "nothing was ever pruned here" would be wrong. Both `devp
112/// stats` and its `--json` document quote this version so the gap is explained rather than
113/// looking like data loss. It is deliberately not [`VERSION`]: it names the release the
114/// format changed in, and does not move again.
115pub const HISTORY_STARTS_AT: &str = "1.1.0";
116
117/// Default idle threshold in days before a repository is eligible for pruning.
118pub const DEFAULT_IDLE_DAYS: u64 = 15;
119
120/// Default idle threshold for *build-tree* directories, in days.
121///
122/// Applies to every adapter that answers [`crate::adapters::PackageManager::opt_in`].
123/// Deliberately longer than [`DEFAULT_IDLE_DAYS`],
124/// because those directories come back by recompiling the whole project rather than by
125/// re-downloading a dependency tree, so the bar for "nobody will miss this" sits
126/// higher. The engine applies `max(build_idle_days, idle_days)`.
127///
128/// Three times the dependency window and no more: 60 days was long enough that a
129/// project touched once a quarter never became a candidate at all, which is not
130/// caution, it is the feature never firing.
131pub const DEFAULT_BUILD_IDLE_DAYS: u64 = 45;
132
133/// The per-manager cache size cap `devp config wizard` offers, in gibibytes.
134///
135/// Not a default: `cache_max_gb` is empty until someone puts a number in it, and an
136/// empty map means no cache is ever called too big. This is only the figure the wizard
137/// pre-fills and the docs recommend, and 10 GiB is where it sits because that is the
138/// size at which a download cache stops being a time-saver and starts being the largest
139/// directory on the disk — a `uv` cache measured on the author's machine had passed it
140/// while every project it served fit in a tenth of that.
141pub const RECOMMENDED_CACHE_MAX_GB: u64 = 10;
142
143/// One gibibyte, for turning `cache_max_gb` into the byte count a cache is measured in.
144pub const BYTES_PER_GIB: u64 = 1024 * 1024 * 1024;
145
146/// Shown while `devp trust` and the configurator ask the OS about the scheduler and
147/// Git hooks, then overwritten in place. Kept here because its width is what the
148/// erase writes over, so the two must not be able to drift apart.
149pub const READING_MACHINE: &str = "Reading this machine (scheduler, Git hooks)...";
150
151/// Default interval in days between background daemon prune runs.
152pub const DEFAULT_CHECK_INTERVAL_DAYS: u64 = 2;
153
154/// Whether the setup pass installs the OS scheduler.
155///
156/// On. A pruner that has to be remembered is a pruner that never runs; the scheduled
157/// pass is the product, not an extra. It is still bounded by everything an interactive
158/// run is bounded by — idle threshold, lockfile verification, per-repo opt-outs — and
159/// `devp daemon uninstall` (or `devp config set auto_daemon false`) removes it.
160pub const DEFAULT_AUTO_DAEMON: bool = true;
161
162/// Whether the setup pass installs the global Git auto-registration hooks.
163///
164/// On, but conditionally: installation is skipped, not forced, when `core.hooksPath`
165/// already belongs to husky, pre-commit or lefthook.
166pub const DEFAULT_AUTO_HOOKS: bool = true;
167
168/// Whether dev-prune installs its missing integrations by itself.
169///
170/// On. The pass runs once per installed version — on first run, and again after an
171/// upgrade — and only creates what is absent. Set to `false`, or export
172/// `DEV_PRUNE_NO_AUTO_SETUP`, to manage the integrations entirely by hand.
173///
174/// The environment variable is symmetric: with it set, `devp uninstall` leaves those
175/// same hand-managed integrations — the scheduler, the agent skills, the install
176/// directories guessed from the home folder — alone too, and says so. "Entirely by
177/// hand" has to include the removal, or the variable's promise only holds until the
178/// day you uninstall.
179pub const DEFAULT_AUTO_SETUP: bool = true;
180
181/// Default for whether `link` and `init` write a `.devprune.json` into repositories
182/// they register.
183///
184/// Off: most repositories are fine on the defaults, and a config file dropped into
185/// every repo is litter. The setting exists for people who tune repositories
186/// individually often enough that creating the file by hand every time is the chore.
187pub const DEFAULT_AUTO_CONFIG: bool = false;
188
189/// Default setting for requiring interactive confirmation before pruning.
190pub const DEFAULT_REQUIRE_CONFIRMATION: bool = true;
191
192/// Language for dev-prune's own headings and summary lines.
193///
194/// English, and English is also the fallback for every key a translation has not
195/// reached yet -- see [`crate::i18n`]. Deliberately not derived from the operating
196/// system locale: a machine configured in one language has said nothing about what
197/// language its owner wants their build tools in.
198pub const DEFAULT_LANGUAGE: &str = "en";
199
200/// Default size floor, in MiB, below which a bloat directory is left alone.
201///
202/// Zero — every recognised directory is a candidate. Raising it trades a little disk
203/// space for fewer reinstalls: deleting a 3 MiB `node_modules` costs a full `npm ci`
204/// and reclaims almost nothing.
205pub const DEFAULT_MIN_SIZE_MB: u64 = 0;
206
207/// How far below a repository root project discovery descends, by default.
208///
209/// Six covers `packages/scope/name/…` monorepo layouts with room to spare while keeping
210/// the walk bounded on repositories with deep source trees. Configurable with
211/// `devp config set scan_depth`, and per repository with `"scan_depth"` in
212/// `.devprune.json`, because "deep enough" is a property of the layout, not of the tool.
213pub const DEFAULT_SCAN_DEPTH: usize = 6;
214
215/// Upper bound accepted for `scan_depth`.
216///
217/// Not a matter of taste. The walk is breadth-first over every directory that is not
218/// excluded, so cost grows with the tree, and a repository with a deep generated tree
219/// (a Bazel `bazel-out`, a `.terraform` provider cache) can turn an unbounded walk into
220/// a multi-minute stall on a background pass nobody is watching.
221pub const MAX_SCAN_DEPTH_LIMIT: usize = 32;
222
223/// Ceiling on the threads `devp status` uses to size repositories.
224///
225/// The scan is one independent file-system walk per repository, so it is bound by the
226/// disk rather than the CPU and oversubscribing the cores is what makes it fast. The
227/// ceiling exists anyway: past this point a spinning disk spends its time seeking
228/// between trees instead of reading them, and a laptop under a background pass should
229/// still be usable.
230pub const STATUS_SCAN_MAX_THREADS: usize = 32;
231
232/// Threads per reported core for the status scan. Above one because the scan waits on
233/// the disk far more than on the CPU; well below what the disk will queue, because past
234/// that point the extra threads only take turns.
235pub const STATUS_SCAN_THREADS_PER_CORE: usize = 2;
236
237/// Overrides the computed status-scan thread count. Clamped to
238/// [`STATUS_SCAN_MAX_THREADS`]; `1` forces a sequential scan.
239pub const STATUS_SCAN_THREADS_ENV: &str = "DEV_PRUNE_SCAN_THREADS";
240
241/// How many lines of a failed command's output are relayed into a report.
242///
243/// A failing `npm ci` prints its whole usage screen. Six lines is enough for the error
244/// and its cause, and short enough that the prune report around it is still readable;
245/// the rest is reachable through the log file the condensed output still names.
246pub const TOOL_OUTPUT_MAX_LINES: usize = 6;
247
248/// Directory names that mean "the contents of this are disposable".
249///
250/// Matched against a repository's *ancestors*, never against the repository directory
251/// itself: a project may legitimately be called `cache`, but a checkout sitting inside
252/// one is something a tool put there. Editor and agent plugin managers clone into
253/// directories like `~/.claude/plugins/cache/temp_git_<id>`, which is nowhere near the OS
254/// temp directory and is deleted just as fast; twenty-eight of those reached one
255/// registry before this list existed.
256pub const EPHEMERAL_ANCESTORS: &[&str] = &["cache", ".cache", "Cache", "Caches", "tmp", ".tmp"];
257
258/// Repository directory *names* that mean the same thing, wherever they are.
259///
260/// The ancestor list above only catches a throwaway clone that a tool was polite enough
261/// to put under a directory called `cache`. These prefixes catch the clone itself:
262/// `temp_git_1787245534782` is a checkout some plugin manager made, named after the
263/// millisecond it made it, and it will be gone before the next prune pass. Registering
264/// one strands a dead entry in the registry the moment the tool cleans up after itself.
265///
266/// A prefix rather than a substring, and deliberately narrow: `temporary-fixes` and
267/// `my-temp-git-notes` are real repositories somebody named badly, and refusing to track
268/// a real workspace is the worse of the two errors.
269pub const EPHEMERAL_REPO_PREFIXES: &[&str] = &["temp_git_", "tmp_git_"];
270
271/// Whether an adapter whose sync command edits tracked manifests may run it.
272///
273/// Off. `cargo generate-lockfile` re-resolves every dependency and rewrites
274/// `Cargo.lock`; `go mod tidy` edits `go.mod` and `go.sum` and can drop requirements.
275/// A cleanup tool that silently changes files Git tracks has done something the user
276/// did not ask for, so these run read-only and this switch is the informed opt-in.
277pub const DEFAULT_ALLOW_MANIFEST_REWRITE: bool = false;
278
279/// Whether the setup pass installs the Git hooks in front of another tool's.
280///
281/// Off. Chaining is behaviour-preserving — every hook is forwarded on and
282/// `devp hook uninstall` restores the original `core.hooksPath` — but it still rewires
283/// somebody else's Git configuration, which is not a thing to do unasked. Turn it on
284/// with `devp config set auto_hooks_chain true`, or do it once with
285/// `devp hook install --chain`.
286pub const DEFAULT_AUTO_HOOKS_CHAIN: bool = false;
287
288/// GitHub releases page, shown whenever an upgrade is relevant.
289pub const RELEASES_URL: &str = "https://github.com/Life-Experimentalist/dev-prune/releases";
290
291/// The shell installer, printed as an upgrade command and re-run by `devp update
292/// --install` when the running binary came from it.
293pub const INSTALL_SH_URL: &str = "https://devprune.vkrishna04.me/install.sh";
294
295/// The PowerShell installer — same two callers as [`INSTALL_SH_URL`].
296pub const INSTALL_PS1_URL: &str = "https://devprune.vkrishna04.me/install.ps1";
297
298/// GitHub API endpoint for the latest published release.
299///
300/// Contacted by `devp update` and by the interval-gated check behind
301/// `run`/`status`/`init` (off via `update_check false` or `DEV_PRUNE_OFFLINE`). See the
302/// network policy in `docs/PRIVACY.md`.
303///
304/// This answers with the newest release GitHub has marked *latest*, which is the newest
305/// binary release and nothing else: the extension's releases are published with
306/// `make_latest: false` precisely so they never surface here. They must not. This URL's
307/// answer is fed to [`compare_versions`](crate::commands::update::compare_versions)
308/// after a leading `v` is stripped, and a `vscode-v0.4.0` tag arriving here would leave
309/// every installed copy unable to compare its own version for as long as that release
310/// stayed newest.
311pub const LATEST_RELEASE_API_URL: &str =
312    "https://api.github.com/repos/Life-Experimentalist/dev-prune/releases/latest";
313
314/// GitHub API endpoint listing releases newest-first, for the extension `.vsix`.
315///
316/// The extension ships on its own tags (`vscode-v*`) and its own release page, because
317/// its version is its own and it changes on its own schedule — see
318/// `.github/workflows/release-extension.yml`. That is also why this is a listing rather
319/// than [`LATEST_RELEASE_API_URL`]: there is no "latest release whose tag starts with"
320/// endpoint, so the caller walks the page and takes the first match.
321///
322/// One page is enough by a wide margin. The extension would have to go a hundred binary
323/// releases without a single release of its own before its newest fell off the end, and
324/// the fallback degrades to "install it by hand" rather than to anything wrong.
325pub const RELEASES_LIST_API_URL: &str =
326    "https://api.github.com/repos/Life-Experimentalist/dev-prune/releases?per_page=100";
327
328/// Tag prefix identifying a release of the VS Code extension rather than of the binary.
329pub const VSCODE_RELEASE_TAG_PREFIX: &str = "vscode-v";
330
331/// Where a release's assets live, with `{tag}` standing in for `v1.4.0`.
332///
333/// Used by `devp update --install` to fetch the uncompressed binary and its `.sha256`
334/// sidecar. Deliberately the plain `releases/download` path rather than an API endpoint:
335/// it needs no token, is not rate-limited per-IP the way `api.github.com` is, and is the
336/// same URL a person would click on the release page.
337pub const RELEASE_DOWNLOAD_BASE: &str =
338    "https://github.com/Life-Experimentalist/dev-prune/releases/download";
339
340/// Where a SHA-256 becomes a scan report, with the digest appended as the last segment.
341///
342/// `devp trust` prints one of these per executable it owns. It is a *lookup* by hash and
343/// nothing more: the digest is computed locally, the URL is printed rather than fetched,
344/// and no part of dev-prune ever uploads a file anywhere. The reason it exists is that an
345/// antivirus judges the bytes on the disk in front of it, not the asset on a release
346/// page — so the only hash worth showing someone is the one their own copy has.
347pub const VIRUSTOTAL_FILE_BASE: &str = "https://www.virustotal.com/gui/file";
348
349/// The release-asset name for one platform, without the `.sha256` suffix.
350///
351/// This is a contract with the packaging steps in `.github/workflows/release.yml`, which
352/// build these exact names. A mismatch is not a compile error and not a test failure —
353/// it is a self-update that 404s on the day of a release — so the two are commented as
354/// referring to each other.
355///
356/// `None` on a platform the release does not build for, which is how a source build on,
357/// say, FreeBSD declines the direct route instead of downloading a Linux binary.
358pub fn release_asset_name(version: &str) -> Option<String> {
359    let os = match std::env::consts::OS {
360        "windows" => "windows",
361        "macos" => "darwin",
362        "linux" => "linux",
363        _ => return None,
364    };
365    // The release publishes `x64`/`arm64`/`x86`, not Rust's target-arch spellings.
366    let arch = match std::env::consts::ARCH {
367        "x86_64" => "x64",
368        "aarch64" => "arm64",
369        "x86" => "x86",
370        _ => return None,
371    };
372    // Only Windows ships a 32-bit build; on any other OS `x86` has no asset.
373    if arch == "x86" && os != "windows" {
374        return None;
375    }
376    let ext = if os == "windows" { ".exe" } else { "" };
377    Some(format!("dev-prune-v{version}-{os}-{arch}{ext}"))
378}
379
380/// Whether the periodic release check runs. On by default — see `Settings::update_check`.
381pub const DEFAULT_UPDATE_CHECK: bool = true;
382
383/// Whether a known-newer release installs itself at the end of a prune pass. On by
384/// default — see `Settings::auto_update`.
385pub const DEFAULT_AUTO_UPDATE: bool = true;
386
387/// Whether the installed version is pinned where it is. Off by default, and the only
388/// setting that outranks every other update path -- see `Settings::version_lock`.
389pub const DEFAULT_VERSION_LOCK: bool = false;
390
391/// Default interval, in days, between automatic release checks.
392///
393/// A week. Frequent enough that a security fix is not missed for long, rare enough that
394/// it is invisible in day-to-day use. Override with
395/// `devp config set update_check_interval_days`.
396pub const UPDATE_CHECK_INTERVAL_DAYS: i64 = 7;
397
398/// Default timeout for the release check. Short on purpose — this is a convenience,
399/// and a user waiting on a hung socket is worse than not knowing. Override with
400/// `devp config set update_check_timeout_secs` when a proxy needs longer.
401pub const UPDATE_CHECK_TIMEOUT_SECS: u64 = 5;
402
403/// Timeout for downloading a release binary in `devp update --install`.
404///
405/// Far longer than [`UPDATE_CHECK_TIMEOUT_SECS`], which only reads a few hundred bytes
406/// of JSON: this pulls several megabytes, and a slow connection is not an error.
407pub const UPDATE_DOWNLOAD_TIMEOUT_SECS: u64 = 300;
408
409/// Name of the registry JSON file.
410pub const REGISTRY_FILENAME: &str = "registry.json";
411
412/// Config directory name under user config root.
413pub const CONFIG_DIR_NAME: &str = "dev-prune";
414
415/// Global environment variable name to override config directory location.
416pub const ENV_CONFIG_DIR_OVERRIDE: &str = "DEV_PRUNE_CONFIG_DIR";
417
418/// Environment variable that suppresses the automatic setup pass entirely.
419///
420/// For images, CI and anyone who wants the binary and nothing else. `devp setup` still
421/// works when it is set — this only governs the unattended pass.
422pub const ENV_NO_AUTO_SETUP: &str = "DEV_PRUNE_NO_AUTO_SETUP";
423
424/// Environment variable that keeps the process off the network entirely — the release
425/// check and the extension-download fallback alike. Set by the test suites, useful on
426/// air-gapped machines; the durable per-user switch is
427/// `devp config set update_check false`.
428pub const ENV_OFFLINE: &str = "DEV_PRUNE_OFFLINE";
429
430/// Environment variable that stops both install scripts from asking anything.
431///
432/// The scripts offer to migrate a copy another package manager owns, and `devp install
433/// --channel installer` re-runs the script that made the offer. Without this the offer
434/// would be made again by that inner run, to a user who has already answered it — the
435/// same copy is still on PATH until the uninstall at the end. It is also the switch for
436/// a provisioning script that wants the install and none of the conversation.
437///
438/// Read by `scripts/install.sh`, `scripts/install.ps1`, and set by
439/// `src/commands/install.rs` on the child it spawns.
440pub const ENV_NO_MIGRATE_PROMPT: &str = "DEV_PRUNE_NO_MIGRATE_PROMPT";
441
442/// The install receipt, written beside the managed binary by whichever installer put it
443/// there. See [`crate::receipt`].
444///
445/// Also written by `scripts/install.sh` and `scripts/install.ps1`, by hand, in their own
446/// languages — which is why the field names have a test of their own.
447pub const INSTALL_RECEIPT_FILE: &str = "install.json";
448
449/// Set to any value to keep every full-screen view from opening, so the line-by-line
450/// fallback runs instead.
451///
452/// For agents and wrappers that hold a real terminal — the terminal test alone cannot
453/// tell them apart from a person, and a full-screen view waiting on a keypress from
454/// something that will never send one is a hang.
455pub const ENV_NO_TUI: &str = "DEV_PRUNE_NO_TUI";
456
457/// Environment variable that overrides the `language` setting for one invocation.
458///
459/// What a script or a CI job sets when it wants output in a known language whatever the
460/// machine is configured for. An unrecognised code falls back to [`DEFAULT_LANGUAGE`]
461/// rather than failing, because this is read before the command runs and a typo in a
462/// cosmetic setting should not stop a prune.
463pub const ENV_LANGUAGE: &str = "DEV_PRUNE_LANG";
464
465/// Windows environment variable that carries the *machine's* architecture when the
466/// running process is emulated.
467///
468/// `std::env::consts::ARCH` is baked in at compile time and only ever describes the
469/// binary. Windows sets this one under WOW64 and under ARM64 emulation, which is the
470/// only way a 32-bit build can tell that it is running on a 64-bit machine.
471/// `scripts/install.ps1` reads the same variable to choose which asset to download.
472pub const ENV_NATIVE_ARCH: &str = "PROCESSOR_ARCHITEW6432";
473
474/// Filename that, when present in a repo root, causes dev-prune to skip that repo entirely.
475///
476/// Create this file with: `touch ignore.devprune.json`
477pub const DEVPRUNE_IGNORE_FILE: &str = "ignore.devprune.json";
478
479/// Home-relative directory names that conventionally hold a developer's repositories.
480///
481/// Probed by name — existence is one `stat` each — when discovery has no registered
482/// repository to work outwards from. Deliberately a list of conventions rather than a
483/// walk of the home directory: `~` also contains `Library`, `AppData` and whatever a
484/// cloud-sync client has decided to materialise, and none of that is anybody's code.
485///
486/// `Documents/GitHub` is GitHub Desktop's default, `source/repos` is Visual Studio's,
487/// and `go/src` is the layout every pre-modules Go install still has.
488pub const CODE_ROOT_NAMES: &[&str] = &[
489    "Code",
490    "code",
491    "Projects",
492    "projects",
493    "Developer",
494    "Development",
495    "dev",
496    "src",
497    "repos",
498    "git",
499    "work",
500    "workspace",
501    "Documents/GitHub",
502    "source/repos",
503    "go/src",
504];
505
506/// Fewest path components a directory must have before discovery will scan it.
507///
508/// A repository cloned directly into the home directory has `~` as its parent, and
509/// "scan the parent of every registered repository" would then mean walking the whole
510/// home directory — every cache, every application-support tree, every cloud mount. The
511/// depth floor is what stops one repository in the wrong place from turning a cheap
512/// neighbourhood scan into a full-disk crawl.
513pub const MIN_DISCOVERY_ROOT_DEPTH: usize = 2;
514
515/// Default for whether the scheduled pass looks for unregistered repositories by itself.
516///
517/// On. The Git hook registers a repository the first time you commit in it, which leaves
518/// out every repository you cloned and have not committed to — exactly the idle ones
519/// worth pruning. Discovery is also the only way an assistant driving the tool learns
520/// about repositories nobody has mentioned to it.
521///
522/// Safe to have on by default because discovery only *registers*. A newly registered
523/// repository is still pruned only once it is idle past `idle_days`, only where a
524/// lockfile proves every directory recoverable, and only after the safety invariants
525/// pass — so the worst outcome of a wrong guess is a row in `devp status`.
526pub const DEFAULT_AUTO_DISCOVER: bool = true;
527
528/// Default timeout in seconds for lockfile enforcement / CLI commands (10 minutes).
529pub const DEFAULT_COMMAND_TIMEOUT_SECS: u64 = 600;
530
531/// Directory name pnpm gives a store it has to put on a volume of its own.
532///
533/// pnpm hardlinks its store into every `node_modules` it fills, and a hardlink cannot
534/// cross a filesystem. A project on a filesystem that is not the home directory's
535/// therefore gets a store at the root of *its* filesystem instead — `V:\\.pnpm-store` on
536/// a second Windows drive, `/mnt/data/.pnpm-store` on Linux, `/Volumes/Work/.pnpm-store`
537/// on macOS. `devp caches` looks for one on every volume that holds a registered
538/// repository, because `pnpm store path` only ever answers for the volume it is run on.
539pub const PNPM_VOLUME_STORE_DIR: &str = ".pnpm-store";
540
541/// Timeout for the "where does your cache live?" queries `devp caches` makes.
542///
543/// Deliberately not `command_timeout_secs`. That ceiling is sized for `npm ci` and
544/// `cargo metadata`; `npm config get cache` prints one line and returns. A query that
545/// has not answered in five seconds is a broken installation, and the report is better
546/// off falling back to the conventional path than waiting ten minutes for it.
547pub const CACHE_QUERY_TIMEOUT_SECS: u64 = 5;
548
549/// Timeout for asking a container engine how much disk it is using.
550///
551/// Longer than [`CACHE_QUERY_TIMEOUT_SECS`], because `docker system df` is not a config
552/// lookup: the daemon walks every image layer, container and build-cache record to
553/// answer it, and on a store with hundreds of images that is genuinely a few seconds. A
554/// daemon that is not running refuses in milliseconds either way, which is the case this
555/// ceiling is not for.
556pub const CONTAINER_QUERY_TIMEOUT_SECS: u64 = 20;
557
558/// Ceiling for one `devp caches clear` step.
559///
560/// Ten minutes, not the five seconds a query gets: `go clean -modcache` and deleting a
561/// multi-gigabyte `~/.gradle/caches` are genuinely slow, and on Windows every file in a
562/// module cache is read-only, so the delete is a chmod-and-unlink per file. A clear that
563/// has not finished in ten minutes is wedged, and killing it leaves a partially emptied
564/// cache the manager refills on its own.
565pub const CACHE_CLEAR_TIMEOUT_SECS: u64 = 600;
566
567/// Documentation URL for troubleshooting lockfile and pruning failures.
568pub const TROUBLESHOOTING_URL: &str = "https://devprune.vkrishna04.me/docs/troubleshooting";
569/// Name of the structured per-repository configuration file stored inside repo roots.
570pub const PER_REPO_CONFIG_FILE: &str = ".devprune.json";
571
572/// Name of the committed, team-wide half of a repository's configuration.
573///
574/// Same shape and same schema as [`PER_REPO_CONFIG_FILE`], and the opposite intent.
575/// `.devprune.json` is written into `.git/info/exclude` so one person's answer stays one
576/// person's; this one is meant to be `git add`-ed, so that "nobody prunes this
577/// repository" is a fact a fresh clone already knows rather than something every
578/// teammate has to be told. The `project.` prefix rather than a new extension is what
579/// keeps one JSON schema covering both files.
580pub const PROJECT_REPO_CONFIG_FILE: &str = "project.devprune.json";
581
582/// The adapter name the declared-directory pass answers to.
583///
584/// Not a package manager and not in `get_all_adapters()`, but it appears in the same
585/// column of the same report, so it needs the same kind of name — and `--only`,
586/// `--skip` and `disabled_adapters` all match on that column. Naming it here is what
587/// keeps the filter, the engine and the report agreeing on the spelling.
588pub const DECLARED_ADAPTER_NAME: &str = "declared";
589
590/// Public URL for the JSON Schema used by IDEs for .devprune.json IntelliSense.
591pub const JSON_SCHEMA_URL: &str = "https://devprune.vkrishna04.me/schemas/v1/devprune.schema.json";
592
593/// Directory under the user's home that marks a Claude Code installation.
594///
595/// Its presence is how the setup pass decides the machine has an agent to install the
596/// skill for; the directory itself is only ever created by Claude Code.
597pub const CLAUDE_HOME_DIR: &str = ".claude";
598
599/// Subdirectory of an agent's home where Agent Skills live, one directory per skill.
600pub const AGENT_SKILLS_SUBDIR: &str = "skills";
601
602/// Marketplace identifier (`publisher.name`) of the VS Code extension, as understood
603/// by `code --install-extension`.
604pub const VSCODE_EXTENSION_ID: &str = "VKrishna04.dev-prune";
605
606/// The WinGet package identifier, as published in `packaging/winget/` and in the
607/// manifests submitted to microsoft/winget-pkgs. `devp update` and `devp uninstall` name
608/// it back to the user, so a typo here sends someone to a command that does not resolve.
609pub const WINGET_PACKAGE_ID: &str = "VKrishna04.dev-prune";
610
611/// The Homebrew tap that carries the formula, as `brew tap` takes it. Not homebrew-core:
612/// plain `brew install dev-prune` resolves there, and that has a notability bar this
613/// project has not cleared. See `docs/DISTRIBUTION.md`.
614pub const HOMEBREW_TAP: &str = "Life-Experimentalist/tap";
615
616/// The Scoop bucket name and the repository behind it. `scoop bucket add` takes both,
617/// and the name is what `scoop install` then resolves `dev-prune` against.
618pub const SCOOP_BUCKET_NAME: &str = "life-experimentalist";
619/// Repository URL for [`SCOOP_BUCKET_NAME`].
620pub const SCOOP_BUCKET_URL: &str = "https://github.com/Life-Experimentalist/scoop-bucket";
621
622/// Where a person can read about the extension before installing it.
623///
624/// The offer prints all three. The two registries carry the same build — the release
625/// `.vsix` — but a machine that trusts one may not have the other, and someone who
626/// wants to read the source before letting anything into their editor needs neither.
627pub const VSCODE_MARKETPLACE_URL: &str =
628    "https://marketplace.visualstudio.com/items?itemName=VKrishna04.dev-prune";
629/// The Open VSX listing, which is what VSCodium, Cursor and Windsurf resolve against.
630pub const OPENVSX_URL: &str = "https://open-vsx.org/extension/VKrishna04/dev-prune";
631
632/// Name of the Windows Task Scheduler task the daemon registers.
633pub const WINDOWS_TASK_NAME: &str = "DevPrune";
634/// File name of the windowless scheduler binary — the same CLI built for the GUI
635/// subsystem, the relationship `pythonw.exe` has to `python.exe`. A `[[bin]]` target, so
636/// it ships in the Windows archives and `cargo install` places it; nothing generates it
637/// on a user's machine.
638pub const WINDOWS_WINDOWLESS_BIN: &str = "devpw.exe";
639/// Marker file (in the config directory) recording that this machine's Task Scheduler
640/// refused the sessionless (S4U) task registration, so setup keeps the console task
641/// instead of retrying the upgrade on every pass.
642///
643/// Named for what the task *is* and not for what it is not: this value lands in the
644/// binary's string table a few bytes from `devpw.exe`, and "devpw" next to "hidden" is
645/// what a reviewer running `strings` reads first. Nothing here is concealed from
646/// anyone — the task is listed in Task Scheduler under its own name and the marker is
647/// an empty file in the config directory — so the vocabulary must not imply otherwise.
648pub const SCHEDULER_WINDOWLESS_REFUSED_MARKER: &str = "scheduler-windowless-refused";
649
650/// Label of the macOS LaunchAgent the daemon registers (also names its plist file).
651pub const MACOS_LAUNCHD_LABEL: &str = "com.devprune.daemon";
652
653/// Where `devp skill --agent cursor` writes the per-repository rules.
654pub const CURSOR_RULES_FILE: &str = ".cursor/rules/dev-prune.mdc";
655
656/// Where `devp skill --agent windsurf` writes the per-repository rules.
657pub const WINDSURF_RULES_FILE: &str = ".windsurf/rules/dev-prune.md";
658
659/// Where `devp skill --agent antigravity` writes the per-repository rules —
660/// Antigravity (Google) reads workspace rules from `.agent/rules/`.
661pub const ANTIGRAVITY_RULES_FILE: &str = ".agent/rules/dev-prune.md";
662
663/// Where `devp skill --agent cline` writes its rules (Cline reads every file in the
664/// `.clinerules/` directory).
665pub const CLINE_RULES_FILE: &str = ".clinerules/dev-prune.md";
666
667/// Where `devp skill --agent agents-md` writes its marked block — the cross-tool
668/// convention read by Codex, Jules, Amp, Antigravity and others.
669pub const AGENTS_MD_FILE: &str = "AGENTS.md";
670
671/// Where `devp skill --agent roo` writes its rules (Roo Code reads every file in
672/// `.roo/rules/`).
673pub const ROO_RULES_FILE: &str = ".roo/rules/dev-prune.md";
674
675/// Where `devp skill --agent kilocode` writes its rules (Kilo Code reads every file in
676/// `.kilocode/rules/`).
677pub const KILOCODE_RULES_FILE: &str = ".kilocode/rules/dev-prune.md";
678
679/// Where `devp skill --agent continue` writes its rules (Continue reads every file in
680/// `.continue/rules/`).
681pub const CONTINUE_RULES_FILE: &str = ".continue/rules/dev-prune.md";
682
683/// Where `devp skill --agent amazon-q` writes its rules (Amazon Q Developer reads every
684/// file in `.amazonq/rules/`).
685pub const AMAZON_Q_RULES_FILE: &str = ".amazonq/rules/dev-prune.md";
686
687/// Where `devp skill --agent kiro` writes its rules (Kiro reads every file in
688/// `.kiro/steering/`).
689pub const KIRO_STEERING_FILE: &str = ".kiro/steering/dev-prune.md";
690
691/// Where `devp skill --agent trae` writes its rules (Trae reads every file in
692/// `.trae/rules/`).
693pub const TRAE_RULES_FILE: &str = ".trae/rules/dev-prune.md";
694
695/// The shared file `devp skill --agent junie` owns a marked block inside — JetBrains
696/// Junie reads one guidelines file, not a directory.
697pub const JUNIE_GUIDELINES_FILE: &str = ".junie/guidelines.md";
698
699/// The shared file `devp skill --agent gemini` owns a marked block inside — the Gemini
700/// CLI reads one context file per repository.
701pub const GEMINI_MD_FILE: &str = "GEMINI.md";
702
703/// The shared file `devp skill --agent zed` owns a marked block inside. Zed reads
704/// `.rules` ahead of every other convention, so a repository that also has an
705/// `AGENTS.md` still needs this one.
706pub const ZED_RULES_FILE: &str = ".rules";
707
708/// The shared file `devp skill --agent aider` owns a marked block inside. Aider is the
709/// one target that does not read its file on its own: `CONVENTIONS.md` is loaded only
710/// by `aider --read CONVENTIONS.md` or a `read: CONVENTIONS.md` line in
711/// `.aider.conf.yml`, which is why writing it prints that instruction.
712pub const AIDER_CONVENTIONS_FILE: &str = "CONVENTIONS.md";
713
714/// The shared file `devp skill --agent copilot` owns a marked block inside.
715pub const COPILOT_INSTRUCTIONS_FILE: &str = ".github/copilot-instructions.md";
716
717/// Markers around the block in [`COPILOT_INSTRUCTIONS_FILE`] that dev-prune manages.
718/// Everything outside them belongs to the user and is never touched.
719pub const RULES_BLOCK_START: &str = "<!-- dev-prune:rules:start -->";
720pub const RULES_BLOCK_END: &str = "<!-- dev-prune:rules:end -->";
721
722/// The phrase Git uses when it refuses a working tree owned by another account.
723///
724/// Matched against Git's own stderr rather than parsed: the message is twelve lines
725/// long, ten of which are identical for every repository refused, and `devp run`
726/// groups every repository sharing this cause under one explanation and one fix
727/// instead of reprinting those ten lines per repository.
728pub const GIT_DUBIOUS_OWNERSHIP: &str = "detected dubious ownership";
729
730/// The phrase Git uses when the path it was pointed at is not a working tree at all.
731///
732/// Same reasoning as [`GIT_DUBIOUS_OWNERSHIP`]: one cause, one fix, one paragraph.
733pub const GIT_NOT_A_REPOSITORY: &str = "not a git repository";