Skip to main content

dev_prune/
constants.rs

1// Copyright 2026 VKrishna04
2// SPDX-License-Identifier: Apache-2.0
3
4// Centralized application constants and default configurations.
5//
6// Serves as the single source of truth for app metadata, versioning,
7// default thresholds, and file paths.
8
9/// Application crate version derived dynamically from `Cargo.toml`.
10pub const VERSION: &str = env!("CARGO_PKG_VERSION");
11
12/// The marker `devp trust` looks for when reading another copy's version.
13///
14/// A binary cannot be asked its version without running it, and `devp trust` must not
15/// run the files it reports on — on Windows one of them is `devpw.exe`, which is linked
16/// for the GUI subsystem, so a shell that invokes it waits forever. So every build
17/// carries its version as a fixed string in its own bytes and the report reads it off
18/// the disk.
19pub const VERSION_STAMP_MARK: &str = "dev-prune-build-stamp/";
20
21/// The stamp this build carries, which is what the scan above finds.
22///
23/// The mark is written out again here rather than composed from `VERSION_STAMP_MARK`,
24/// because `concat!` takes literals and not constants. That leaves two copies of the
25/// mark in every binary — this one, and the search literal itself — so the scan
26/// validates what follows each hit and keeps the first that parses as a version rather
27/// than trusting the first hit.
28pub const VERSION_STAMP: &str =
29    concat!("dev-prune-build-stamp/", env!("CARGO_PKG_VERSION"), "/end");
30
31/// The stamp, kept in the compiled binary by being an exported symbol nothing may drop.
32///
33/// `#[used]` binds the compiler and not the linker, and both `/OPT:REF` and
34/// `--gc-sections` are free to remove a static that nothing reads. Exporting the symbol
35/// as well is what survives them. Neither is proof on three platforms, which is why
36/// `trust`'s tests scan the test executable for this string rather than assume it is
37/// there — a stamp the linker quietly removed would turn every version in the report
38/// into "not stamped", and nothing else would notice.
39#[used]
40#[unsafe(no_mangle)]
41pub static DEV_PRUNE_BUILD_STAMP: &str = VERSION_STAMP;
42
43/// Minimum supported Rust version, derived dynamically from `rust-version` in
44/// `Cargo.toml` — which is the single source of truth for the MSRV. Only `cargo
45/// install` users ever meet it; every other channel ships a prebuilt binary.
46pub const MSRV: &str = env!("CARGO_PKG_RUST_VERSION");
47
48/// Application name.
49pub const APP_NAME: &str = "dev-prune";
50
51/// Author of dev-prune.
52pub const AUTHOR: &str = "VKrishna04";
53
54/// Canonical source repository.
55///
56/// The one in `Cargo.toml` is only visible to people who already found the crate. This
57/// one is compiled into the binary, so a copy of the executable still says where it came
58/// from.
59pub const REPO_URL: &str = "https://github.com/Life-Experimentalist/dev-prune";
60
61/// Project homepage.
62pub const HOMEPAGE_URL: &str = "https://devprune.vkrishna04.me";
63
64/// The one-line credit printed under interactive output.
65///
66/// Deliberately plain text in plain sight: it is not obfuscated, not assembled at
67/// runtime, and not checked anywhere. Anyone may fork this project and change this line
68/// — the Apache-2.0 licence says so, and nothing in the code argues. It exists so that
69/// the common case, someone running the published binary, shows where it came from.
70pub const ATTRIBUTION_LINE: &str =
71    "dev-prune · made with ♥ by VKrishna04 · github.com/Life-Experimentalist/dev-prune";
72
73/// What the banner says the tool is, in one line.
74///
75/// The framing people arrive with is "the `node_modules` cleaner". That was fair when
76/// there were four adapters and has been wrong for a long time — and the banner is the
77/// first screen of every interactive command, so it is the cheapest place to correct it.
78/// No count of package managers here on purpose: a number in a banner is a number that
79/// goes stale the next time an adapter lands.
80pub const TAGLINE: &str = "Every dependency directory on this machine, in one command.";
81
82/// The half of the pitch that is a promise rather than a description.
83///
84/// It sits under [`TAGLINE`] because "deletes directories" is the part a new user is
85/// right to be nervous about, and the answer to it should not be three screens away in
86/// the README. Both halves of the sentence are load-bearing: the lockfile rule is what
87/// the engine actually enforces, and `restore --last-run` is what covers the case where
88/// the rule was satisfied and the user still wanted the directory back. It named `undo`
89/// for six releases, which reverses an `init` or a `link` and has never put a directory
90/// back — the one promise on the first screen pointed at the wrong command.
91pub const TAGLINE_SAFETY: &str =
92    "Only what a lockfile can rebuild — and `devp restore --last-run` puts it back.";
93
94/// The licence sentence under the declaration, in both wizard paths.
95///
96/// Apache-2.0 needs no click-through and this is not one: the licence governs use
97/// whether or not anybody reads this line. It is here because the screen it sits on is
98/// the first thing a new user meets, and a tool that deletes directories should say what
99/// it does and does not promise at that moment rather than in a file called LICENSE.md.
100/// Sections 7 and 8 are named so the disclaimer can be checked rather than taken on
101/// trust.
102pub const LICENCE_NOTICE: &str =
103    "Apache-2.0 sections 7-8: no warranty, no liability. Using it accepts that.";
104
105/// The body of `devp --version`.
106///
107/// Built at runtime rather than with `concat!`, which only takes literals and would mean
108/// spelling the author and the URL a second time. Two copies of a string are two things
109/// that can disagree, and this one exists precisely so that a stray copy of the binary
110/// can still be traced back.
111pub static LONG_VERSION: std::sync::LazyLock<String> = std::sync::LazyLock::new(|| {
112    format!(
113        "{VERSION}\n\
114         author:     {AUTHOR}\n\
115         repository: {REPO_URL}\n\
116         homepage:   {HOMEPAGE_URL}\n\
117         license:    Apache-2.0"
118    )
119});
120
121/// How many prune passes `devp stats` keeps a summary of.
122///
123/// The registry is rewritten in full on every save, so this list is a file-size decision
124/// as much as a display one. Fifty passes is roughly a year of a fortnightly schedule.
125pub const PRUNE_HISTORY_LIMIT: usize = 50;
126
127/// Name of the append-only prune log, beside the registry.
128///
129/// Separate from `registry.json` because the two have opposite shapes. The registry is
130/// rewritten in full on every save and every command loads it, so a per-directory record
131/// of every pass ever run would be paid for by `devp status`. This file is read by one
132/// command.
133pub const PRUNE_LOG_FILENAME: &str = "prune-log.jsonl";
134
135/// How many passes the prune log keeps in full, per-directory detail.
136///
137/// Not the same decision as [`PRUNE_HISTORY_LIMIT`], and deliberately a different number:
138/// that one is four integers per pass inside a file every command parses, this one is a
139/// line per pass in a file only `devp history` opens. A hundred passes of a realistic
140/// size is well under a megabyte; the oldest come off the front.
141pub const PRUNE_LOG_LIMIT: usize = 100;
142
143/// The release `devp history` starts recording per-directory detail in.
144///
145/// Passes older than this exist — [`PRUNE_HISTORY_LIMIT`] summaries of them are in the
146/// registry — but with four numbers each and no directory list. `devp history` shows them
147/// anyway, marked, because a machine that has pruned for a year and shows an empty log
148/// reads as data loss rather than as a format that changed.
149pub const PRUNE_LOG_STARTS_AT: &str = "1.17.0";
150
151/// How many restore measurements one adapter's throughput average is worth.
152///
153/// Past this, the running totals are halved before the new sample is added, so the
154/// average follows the machine rather than remembering a disk it no longer has. A plain
155/// lifetime mean would quote a spinning-rust number years after the SSD went in.
156pub const RESTORE_RATE_SAMPLE_CAP: u32 = 20;
157
158/// The shortest restore worth learning a throughput from, in milliseconds.
159///
160/// A restore that returned in under this is a manager deciding it had nothing to do —
161/// the packages were still in its cache, or already on disk. Averaging those in would
162/// claim a rate no cold restore can reach.
163pub const RESTORE_RATE_MIN_MILLIS: u64 = 250;
164
165/// The release that started recording per-repository totals and the pass history.
166///
167/// A machine that pruned for months on 1.0.0 has a large lifetime total and no history at
168/// all, and reading that as "nothing was ever pruned here" would be wrong. Both `devp
169/// stats` and its `--json` document quote this version so the gap is explained rather than
170/// looking like data loss. It is deliberately not [`VERSION`]: it names the release the
171/// format changed in, and does not move again.
172pub const HISTORY_STARTS_AT: &str = "1.1.0";
173
174/// Default idle threshold in days before a repository is eligible for pruning.
175pub const DEFAULT_IDLE_DAYS: u64 = 15;
176
177/// Default idle threshold for *build-tree* directories, in days.
178///
179/// Applies to every adapter that answers [`crate::adapters::PackageManager::opt_in`].
180/// Deliberately longer than [`DEFAULT_IDLE_DAYS`],
181/// because those directories come back by recompiling the whole project rather than by
182/// re-downloading a dependency tree, so the bar for "nobody will miss this" sits
183/// higher. The engine applies `max(build_idle_days, idle_days)`.
184///
185/// Three times the dependency window and no more: 60 days was long enough that a
186/// project touched once a quarter never became a candidate at all, which is not
187/// caution, it is the feature never firing.
188pub const DEFAULT_BUILD_IDLE_DAYS: u64 = 45;
189
190/// The cache size cap the first run suggests, in gibibytes.
191///
192/// Not a default: `cache_max_gb` is empty until someone puts a number in it, and an
193/// empty map means no cache is ever called too big. This is the figure the suggestions
194/// screen and `devp config recommended` offer, and 10 GiB is where it sits because that
195/// is the size at which a download cache stops being a time-saver and starts being the
196/// largest directory on the disk — a `uv` cache measured on the author's machine had
197/// passed it while every project it served fit in a tenth of that.
198pub const RECOMMENDED_CACHE_MAX_GB: u64 = 10;
199
200/// The `cache_max_gb` key that caps every manager without naming one.
201///
202/// A word rather than `*`, because the caps are typed at a shell: a glob would need
203/// quoting in every example the docs print and in every one somebody copies, and would
204/// be silently expanded by the shells that do not need it. `default=10,npm=4` also says
205/// what it does without a legend.
206pub const CACHE_CAP_DEFAULT_KEY: &str = "default";
207
208/// What the first run suggests for `cache_max_gb`.
209///
210/// [`RECOMMENDED_CACHE_MAX_GB`] written out, because the suggestion table holds
211/// `&'static str` values and there is no formatting at compile time. A test in
212/// `commands::config` fails if the two ever stop agreeing.
213pub const RECOMMENDED_CACHE_CAP: &str = "default=10";
214
215/// One gibibyte, for turning `cache_max_gb` into the byte count a cache is measured in.
216pub const BYTES_PER_GIB: u64 = 1024 * 1024 * 1024;
217
218/// Shown while `devp trust` and the configurator ask the OS about the scheduler and
219/// Git hooks, then overwritten in place. Kept here because its width is what the
220/// erase writes over, so the two must not be able to drift apart.
221pub const READING_MACHINE: &str = "Reading this machine (scheduler, Git hooks)...";
222
223/// Default interval in days between background daemon prune runs.
224pub const DEFAULT_CHECK_INTERVAL_DAYS: u64 = 2;
225
226/// Whether the setup pass installs the OS scheduler.
227///
228/// On. A pruner that has to be remembered is a pruner that never runs; the scheduled
229/// pass is the product, not an extra. It is still bounded by everything an interactive
230/// run is bounded by — idle threshold, lockfile verification, per-repo opt-outs — and
231/// `devp daemon uninstall` (or `devp config set auto_daemon false`) removes it.
232pub const DEFAULT_AUTO_DAEMON: bool = true;
233
234/// Whether the setup pass installs the global Git auto-registration hooks.
235///
236/// On, but conditionally: installation is skipped, not forced, when `core.hooksPath`
237/// already belongs to husky, pre-commit or lefthook.
238pub const DEFAULT_AUTO_HOOKS: bool = true;
239
240/// Whether dev-prune installs its missing integrations by itself.
241///
242/// On. The pass runs once per installed version — on first run, and again after an
243/// upgrade — and only creates what is absent. Set to `false`, or export
244/// `DEV_PRUNE_NO_AUTO_SETUP`, to manage the integrations entirely by hand.
245///
246/// The environment variable is symmetric: with it set, `devp uninstall` leaves those
247/// same hand-managed integrations — the scheduler, the agent skills, the install
248/// directories guessed from the home folder — alone too, and says so. "Entirely by
249/// hand" has to include the removal, or the variable's promise only holds until the
250/// day you uninstall.
251pub const DEFAULT_AUTO_SETUP: bool = true;
252
253/// Default for whether `link` and `init` write a `.devprune.json` into repositories
254/// they register.
255///
256/// Off: most repositories are fine on the defaults, and a config file dropped into
257/// every repo is litter. The setting exists for people who tune repositories
258/// individually often enough that creating the file by hand every time is the chore.
259pub const DEFAULT_AUTO_CONFIG: bool = false;
260
261/// Default setting for requiring interactive confirmation before pruning.
262pub const DEFAULT_REQUIRE_CONFIRMATION: bool = true;
263
264/// Language for dev-prune's own headings and summary lines.
265///
266/// English, and English is also the fallback for every key a translation has not
267/// reached yet -- see [`crate::i18n`]. Deliberately not derived from the operating
268/// system locale: a machine configured in one language has said nothing about what
269/// language its owner wants their build tools in.
270pub const DEFAULT_LANGUAGE: &str = "en";
271
272/// Default size floor, in MiB, below which a bloat directory is left alone.
273///
274/// Zero — every recognised directory is a candidate. Raising it trades a little disk
275/// space for fewer reinstalls: deleting a 3 MiB `node_modules` costs a full `npm ci`
276/// and reclaims almost nothing.
277pub const DEFAULT_MIN_SIZE_MB: u64 = 0;
278
279/// How far below a repository root project discovery descends, by default.
280///
281/// Six covers `packages/scope/name/…` monorepo layouts with room to spare while keeping
282/// the walk bounded on repositories with deep source trees. Configurable with
283/// `devp config set scan_depth`, and per repository with `"scan_depth"` in
284/// `.devprune.json`, because "deep enough" is a property of the layout, not of the tool.
285pub const DEFAULT_SCAN_DEPTH: usize = 6;
286
287/// Upper bound accepted for `scan_depth`.
288///
289/// Not a matter of taste. The walk is breadth-first over every directory that is not
290/// excluded, so cost grows with the tree, and a repository with a deep generated tree
291/// (a Bazel `bazel-out`, a `.terraform` provider cache) can turn an unbounded walk into
292/// a multi-minute stall on a background pass nobody is watching.
293pub const MAX_SCAN_DEPTH_LIMIT: usize = 32;
294
295/// Ceiling on the threads `devp status` uses to size repositories.
296///
297/// The scan is one independent file-system walk per repository, so it is bound by the
298/// disk rather than the CPU and oversubscribing the cores is what makes it fast. The
299/// ceiling exists anyway: past this point a spinning disk spends its time seeking
300/// between trees instead of reading them, and a laptop under a background pass should
301/// still be usable.
302pub const STATUS_SCAN_MAX_THREADS: usize = 32;
303
304/// Threads per reported core for the status scan. Above one because the scan waits on
305/// the disk far more than on the CPU; well below what the disk will queue, because past
306/// that point the extra threads only take turns.
307pub const STATUS_SCAN_THREADS_PER_CORE: usize = 2;
308
309/// Overrides the computed status-scan thread count. Clamped to
310/// [`STATUS_SCAN_MAX_THREADS`]; `1` forces a sequential scan.
311pub const STATUS_SCAN_THREADS_ENV: &str = "DEV_PRUNE_SCAN_THREADS";
312
313/// How many lines of a failed command's output are relayed into a report.
314///
315/// A failing `npm ci` prints its whole usage screen. Six lines is enough for the error
316/// and its cause, and short enough that the prune report around it is still readable;
317/// the rest is reachable through the log file the condensed output still names.
318pub const TOOL_OUTPUT_MAX_LINES: usize = 6;
319
320/// Directory names that mean "the contents of this are disposable".
321///
322/// Matched against a repository's *ancestors*, never against the repository directory
323/// itself: a project may legitimately be called `cache`, but a checkout sitting inside
324/// one is something a tool put there. Editor and agent plugin managers clone into
325/// directories like `~/.claude/plugins/cache/temp_git_<id>`, which is nowhere near the OS
326/// temp directory and is deleted just as fast; twenty-eight of those reached one
327/// registry before this list existed.
328pub const EPHEMERAL_ANCESTORS: &[&str] = &["cache", ".cache", "Cache", "Caches", "tmp", ".tmp"];
329
330/// Repository directory *names* that mean the same thing, wherever they are.
331///
332/// The ancestor list above only catches a throwaway clone that a tool was polite enough
333/// to put under a directory called `cache`. These prefixes catch the clone itself:
334/// `temp_git_1787245534782` is a checkout some plugin manager made, named after the
335/// millisecond it made it, and it will be gone before the next prune pass. Registering
336/// one strands a dead entry in the registry the moment the tool cleans up after itself.
337///
338/// A prefix rather than a substring, and deliberately narrow: `temporary-fixes` and
339/// `my-temp-git-notes` are real repositories somebody named badly, and refusing to track
340/// a real workspace is the worse of the two errors.
341pub const EPHEMERAL_REPO_PREFIXES: &[&str] = &["temp_git_", "tmp_git_"];
342
343/// Whether an adapter whose sync command edits tracked manifests may run it.
344///
345/// Off. `cargo generate-lockfile` re-resolves every dependency and rewrites
346/// `Cargo.lock`; `go mod tidy` edits `go.mod` and `go.sum` and can drop requirements.
347/// A cleanup tool that silently changes files Git tracks has done something the user
348/// did not ask for, so these run read-only and this switch is the informed opt-in.
349pub const DEFAULT_ALLOW_MANIFEST_REWRITE: bool = false;
350
351/// Whether the setup pass installs the Git hooks in front of another tool's.
352///
353/// Off. Chaining is behaviour-preserving — every hook is forwarded on and
354/// `devp hook uninstall` restores the original `core.hooksPath` — but it still rewires
355/// somebody else's Git configuration, which is not a thing to do unasked. Turn it on
356/// with `devp config set auto_hooks_chain true`, or do it once with
357/// `devp hook install --chain`.
358pub const DEFAULT_AUTO_HOOKS_CHAIN: bool = false;
359
360/// GitHub releases page, shown whenever an upgrade is relevant.
361pub const RELEASES_URL: &str = "https://github.com/Life-Experimentalist/dev-prune/releases";
362
363/// The shell installer, printed as an upgrade command and re-run by `devp update
364/// --install` when the running binary came from it.
365pub const INSTALL_SH_URL: &str = "https://devprune.vkrishna04.me/install.sh";
366
367/// The PowerShell installer — same two callers as [`INSTALL_SH_URL`].
368pub const INSTALL_PS1_URL: &str = "https://devprune.vkrishna04.me/install.ps1";
369
370/// The release page for the latest published release.
371///
372/// Contacted by `devp update` and by the interval-gated check behind
373/// `run`/`status`/`init` (off via `update_check false` or `DEV_PRUNE_OFFLINE`). See the
374/// network policy in `docs/PRIVACY.md`.
375///
376/// Deliberately the website, not `api.github.com`. GitHub redirects this page to
377/// `releases/tag/<tag>`, and the tag is read out of that `Location` header without
378/// following it — nothing else about the page is needed. The API endpoint that used to
379/// answer the same question allows an unauthenticated address sixty requests an hour
380/// and answered `403` once a busy laptop had spent them, which made `devp update` say
381/// the network was down when it was not. The website has no per-address quota.
382///
383/// Both resolve the release GitHub has marked *latest*, which is the newest binary
384/// release and nothing else: the extension's releases are published with
385/// `make_latest: false` precisely so they never surface here. They must not. The tag
386/// read from here is fed to [`compare_versions`](crate::commands::update::compare_versions)
387/// after a leading `v` is stripped, and a `vscode-v0.4.0` tag arriving here would leave
388/// every installed copy unable to compare its own version for as long as that release
389/// stayed newest.
390pub const LATEST_RELEASE_URL: &str =
391    "https://github.com/Life-Experimentalist/dev-prune/releases/latest";
392
393/// GitHub API endpoint listing releases newest-first, for the extension `.vsix`.
394///
395/// The extension ships on its own tags (`vscode-v*`) and its own release page, because
396/// its version is its own and it changes on its own schedule — see
397/// `.github/workflows/release-extension.yml`. That is also why this is a listing rather
398/// than the redirect behind [`LATEST_RELEASE_URL`]: there is no "latest release whose tag
399/// starts with" endpoint, so the caller walks the page and takes the first match.
400///
401/// One page is enough by a wide margin. The extension would have to go a hundred binary
402/// releases without a single release of its own before its newest fell off the end, and
403/// the fallback degrades to "install it by hand" rather than to anything wrong.
404pub const RELEASES_LIST_API_URL: &str =
405    "https://api.github.com/repos/Life-Experimentalist/dev-prune/releases?per_page=100";
406
407/// Tag prefix identifying a release of the VS Code extension rather than of the binary.
408pub const VSCODE_RELEASE_TAG_PREFIX: &str = "vscode-v";
409
410/// Where a release's assets live, with `{tag}` standing in for `v1.4.0`.
411///
412/// Used by `devp update --install` to fetch the uncompressed binary and its `.sha256`
413/// sidecar. Deliberately the plain `releases/download` path rather than an API endpoint:
414/// it needs no token, is not rate-limited per-IP the way `api.github.com` is, and is the
415/// same URL a person would click on the release page.
416pub const RELEASE_DOWNLOAD_BASE: &str =
417    "https://github.com/Life-Experimentalist/dev-prune/releases/download";
418
419/// Where a SHA-256 becomes a scan report, with the digest appended as the last segment.
420///
421/// `devp trust` prints one of these per executable it owns. It is a *lookup* by hash and
422/// nothing more: the digest is computed locally, the URL is printed rather than fetched,
423/// and no part of dev-prune ever uploads a file anywhere. The reason it exists is that an
424/// antivirus judges the bytes on the disk in front of it, not the asset on a release
425/// page — so the only hash worth showing someone is the one their own copy has.
426pub const VIRUSTOTAL_FILE_BASE: &str = "https://www.virustotal.com/gui/file";
427
428/// The release-asset name for one platform, without the `.sha256` suffix.
429///
430/// This is a contract with the packaging steps in `.github/workflows/release.yml`, which
431/// build these exact names. A mismatch is not a compile error and not a test failure —
432/// it is a self-update that 404s on the day of a release — so the two are commented as
433/// referring to each other.
434///
435/// `None` on a platform the release does not build for, which is how a source build on,
436/// say, FreeBSD declines the direct route instead of downloading a Linux binary.
437pub fn release_asset_name(version: &str) -> Option<String> {
438    let os = match std::env::consts::OS {
439        "windows" => "windows",
440        "macos" => "darwin",
441        "linux" => "linux",
442        _ => return None,
443    };
444    // The release publishes `x64`/`arm64`/`x86`, not Rust's target-arch spellings.
445    let arch = match std::env::consts::ARCH {
446        "x86_64" => "x64",
447        "aarch64" => "arm64",
448        "x86" => "x86",
449        _ => return None,
450    };
451    // Only Windows ships a 32-bit build; on any other OS `x86` has no asset.
452    if arch == "x86" && os != "windows" {
453        return None;
454    }
455    let ext = if os == "windows" { ".exe" } else { "" };
456    Some(format!("dev-prune-v{version}-{os}-{arch}{ext}"))
457}
458
459/// Whether the periodic release check runs. On by default — see `Settings::update_check`.
460pub const DEFAULT_UPDATE_CHECK: bool = true;
461
462/// Whether a known-newer release installs itself at the end of a prune pass. On by
463/// default — see `Settings::auto_update`.
464pub const DEFAULT_AUTO_UPDATE: bool = true;
465
466/// Whether the installed version is pinned where it is. Off by default, and the only
467/// setting that outranks every other update path -- see `Settings::version_lock`.
468pub const DEFAULT_VERSION_LOCK: bool = false;
469
470/// Default interval, in days, between automatic release checks.
471///
472/// A week. Frequent enough that a security fix is not missed for long, rare enough that
473/// it is invisible in day-to-day use. Override with
474/// `devp config set update_check_interval_days`.
475pub const UPDATE_CHECK_INTERVAL_DAYS: i64 = 7;
476
477/// Default timeout for the release check. Short on purpose — this is a convenience,
478/// and a user waiting on a hung socket is worse than not knowing. Override with
479/// `devp config set update_check_timeout_secs` when a proxy needs longer.
480pub const UPDATE_CHECK_TIMEOUT_SECS: u64 = 5;
481
482/// Timeout for downloading a release binary in `devp update --install`.
483///
484/// Far longer than [`UPDATE_CHECK_TIMEOUT_SECS`], which only reads a few hundred bytes
485/// of JSON: this pulls several megabytes, and a slow connection is not an error.
486pub const UPDATE_DOWNLOAD_TIMEOUT_SECS: u64 = 300;
487
488/// Name of the registry JSON file.
489pub const REGISTRY_FILENAME: &str = "registry.json";
490
491/// Config directory name under user config root.
492pub const CONFIG_DIR_NAME: &str = "dev-prune";
493
494/// Global environment variable name to override config directory location.
495pub const ENV_CONFIG_DIR_OVERRIDE: &str = "DEV_PRUNE_CONFIG_DIR";
496
497/// File in the config directory recording the first-run answer to "may dev-prune set
498/// itself up?" — `granted` or `declined`. Its absence means the question has never been
499/// asked, or that `devp uninstall` put it back that way. Separate from the version
500/// stamp on purpose: the stamp is rewritten on every upgrade, and an answer somebody
501/// gave once must survive all of them.
502pub const SETUP_CONSENT_FILE: &str = "setup-consent";
503
504/// Environment variable that suppresses the automatic setup pass entirely.
505///
506/// For images, CI and anyone who wants the binary and nothing else. `devp setup` still
507/// works when it is set — this only governs the unattended pass.
508pub const ENV_NO_AUTO_SETUP: &str = "DEV_PRUNE_NO_AUTO_SETUP";
509
510/// Environment variable that keeps the process off the network entirely — the release
511/// check and the extension-download fallback alike. Set by the test suites, useful on
512/// air-gapped machines; the durable per-user switch is
513/// `devp config set update_check false`.
514pub const ENV_OFFLINE: &str = "DEV_PRUNE_OFFLINE";
515
516/// Environment variable that stops both install scripts from asking anything.
517///
518/// The scripts offer to migrate a copy another package manager owns, and `devp install
519/// --channel installer` re-runs the script that made the offer. Without this the offer
520/// would be made again by that inner run, to a user who has already answered it — the
521/// same copy is still on PATH until the uninstall at the end. It is also the switch for
522/// a provisioning script that wants the install and none of the conversation.
523///
524/// Read by `scripts/install.sh`, `scripts/install.ps1`, and set by
525/// `src/commands/install.rs` on the child it spawns.
526pub const ENV_NO_MIGRATE_PROMPT: &str = "DEV_PRUNE_NO_MIGRATE_PROMPT";
527
528/// The install receipt, written beside the managed binary by whichever installer put it
529/// there. See [`crate::receipt`].
530///
531/// Also written by `scripts/install.sh` and `scripts/install.ps1`, by hand, in their own
532/// languages — which is why the field names have a test of their own.
533pub const INSTALL_RECEIPT_FILE: &str = "install.json";
534
535/// Set to any value to keep every full-screen view from opening, so the line-by-line
536/// fallback runs instead.
537///
538/// For agents and wrappers that hold a real terminal — the terminal test alone cannot
539/// tell them apart from a person, and a full-screen view waiting on a keypress from
540/// something that will never send one is a hang.
541pub const ENV_NO_TUI: &str = "DEV_PRUNE_NO_TUI";
542
543/// Environment variable that overrides the `language` setting for one invocation.
544///
545/// What a script or a CI job sets when it wants output in a known language whatever the
546/// machine is configured for. An unrecognised code falls back to [`DEFAULT_LANGUAGE`]
547/// rather than failing, because this is read before the command runs and a typo in a
548/// cosmetic setting should not stop a prune.
549pub const ENV_LANGUAGE: &str = "DEV_PRUNE_LANG";
550
551/// Windows environment variable that carries the *machine's* architecture when the
552/// running process is emulated.
553///
554/// `std::env::consts::ARCH` is baked in at compile time and only ever describes the
555/// binary. Windows sets this one under WOW64 and under ARM64 emulation, which is the
556/// only way a 32-bit build can tell that it is running on a 64-bit machine.
557/// `scripts/install.ps1` reads the same variable to choose which asset to download.
558pub const ENV_NATIVE_ARCH: &str = "PROCESSOR_ARCHITEW6432";
559
560/// Filename that, when present in a repo root, causes dev-prune to skip that repo entirely.
561///
562/// Create this file with: `touch ignore.devprune.json`
563pub const DEVPRUNE_IGNORE_FILE: &str = "ignore.devprune.json";
564
565/// Home-relative directory names that conventionally hold a developer's repositories.
566///
567/// Probed by name — existence is one `stat` each — when discovery has no registered
568/// repository to work outwards from. Deliberately a list of conventions rather than a
569/// walk of the home directory: `~` also contains `Library`, `AppData` and whatever a
570/// cloud-sync client has decided to materialise, and none of that is anybody's code.
571///
572/// `Documents/GitHub` is GitHub Desktop's default, `source/repos` is Visual Studio's,
573/// and `go/src` is the layout every pre-modules Go install still has.
574pub const CODE_ROOT_NAMES: &[&str] = &[
575    "Code",
576    "code",
577    "Projects",
578    "projects",
579    "Developer",
580    "Development",
581    "dev",
582    "src",
583    "repos",
584    "git",
585    "work",
586    "workspace",
587    "Documents/GitHub",
588    "source/repos",
589    "go/src",
590];
591
592/// Fewest path components a directory must have before discovery will scan it.
593///
594/// A repository cloned directly into the home directory has `~` as its parent, and
595/// "scan the parent of every registered repository" would then mean walking the whole
596/// home directory — every cache, every application-support tree, every cloud mount. The
597/// depth floor is what stops one repository in the wrong place from turning a cheap
598/// neighbourhood scan into a full-disk crawl.
599pub const MIN_DISCOVERY_ROOT_DEPTH: usize = 2;
600
601/// Default for whether the scheduled pass looks for unregistered repositories by itself.
602///
603/// On. The Git hook registers a repository the first time you commit in it, which leaves
604/// out every repository you cloned and have not committed to — exactly the idle ones
605/// worth pruning. Discovery is also the only way an assistant driving the tool learns
606/// about repositories nobody has mentioned to it.
607///
608/// Safe to have on by default because discovery only *registers*. A newly registered
609/// repository is still pruned only once it is idle past `idle_days`, only where a
610/// lockfile proves every directory recoverable, and only after the safety invariants
611/// pass — so the worst outcome of a wrong guess is a row in `devp status`.
612pub const DEFAULT_AUTO_DISCOVER: bool = true;
613
614/// Default timeout in seconds for lockfile enforcement / CLI commands (10 minutes).
615pub const DEFAULT_COMMAND_TIMEOUT_SECS: u64 = 600;
616
617/// Directory name pnpm gives a store it has to put on a volume of its own.
618///
619/// pnpm hardlinks its store into every `node_modules` it fills, and a hardlink cannot
620/// cross a filesystem. A project on a filesystem that is not the home directory's
621/// therefore gets a store at the root of *its* filesystem instead — `V:\\.pnpm-store` on
622/// a second Windows drive, `/mnt/data/.pnpm-store` on Linux, `/Volumes/Work/.pnpm-store`
623/// on macOS. `devp caches` looks for one on every volume that holds a registered
624/// repository, because `pnpm store path` only ever answers for the volume it is run on.
625pub const PNPM_VOLUME_STORE_DIR: &str = ".pnpm-store";
626
627/// Timeout for the "where does your cache live?" queries `devp caches` makes.
628///
629/// Deliberately not `command_timeout_secs`. That ceiling is sized for `npm ci` and
630/// `cargo metadata`; `npm config get cache` prints one line and returns. A query that
631/// has not answered in five seconds is a broken installation, and the report is better
632/// off falling back to the conventional path than waiting ten minutes for it.
633pub const CACHE_QUERY_TIMEOUT_SECS: u64 = 5;
634
635/// Timeout for asking a container engine how much disk it is using.
636///
637/// Longer than [`CACHE_QUERY_TIMEOUT_SECS`], because `docker system df` is not a config
638/// lookup: the daemon walks every image layer, container and build-cache record to
639/// answer it, and on a store with hundreds of images that is genuinely a few seconds. A
640/// daemon that is not running refuses in milliseconds either way, which is the case this
641/// ceiling is not for.
642pub const CONTAINER_QUERY_TIMEOUT_SECS: u64 = 20;
643
644/// Timeout for one reclaim step of `devp caches clear <engine>`.
645///
646/// An order of magnitude above the query, because deleting is not measuring. `docker
647/// image prune -a` on a 30 GB store unlinks tens of thousands of layer files, and on
648/// Docker Desktop it does that inside a VM against a virtual disk. Ten minutes is not an
649/// estimate of how long that takes; it is the point past which the daemon is stuck
650/// rather than slow, and killing the step is better than a command that never returns.
651pub const CONTAINER_PRUNE_TIMEOUT_SECS: u64 = 600;
652
653/// Ceiling for one `devp caches clear` step.
654///
655/// Ten minutes, not the five seconds a query gets: `go clean -modcache` and deleting a
656/// multi-gigabyte `~/.gradle/caches` are genuinely slow, and on Windows every file in a
657/// module cache is read-only, so the delete is a chmod-and-unlink per file. A clear that
658/// has not finished in ten minutes is wedged, and killing it leaves a partially emptied
659/// cache the manager refills on its own.
660pub const CACHE_CLEAR_TIMEOUT_SECS: u64 = 600;
661
662/// Documentation URL for troubleshooting lockfile and pruning failures.
663pub const TROUBLESHOOTING_URL: &str = "https://devprune.vkrishna04.me/docs/troubleshooting";
664/// Name of the structured per-repository configuration file stored inside repo roots.
665pub const PER_REPO_CONFIG_FILE: &str = ".devprune.json";
666
667/// Name of the committed, team-wide half of a repository's configuration.
668///
669/// Same shape and same schema as [`PER_REPO_CONFIG_FILE`], and the opposite intent.
670/// `.devprune.json` is written into `.git/info/exclude` so one person's answer stays one
671/// person's; this one is meant to be `git add`-ed, so that "nobody prunes this
672/// repository" is a fact a fresh clone already knows rather than something every
673/// teammate has to be told. The `project.` prefix rather than a new extension is what
674/// keeps one JSON schema covering both files.
675pub const PROJECT_REPO_CONFIG_FILE: &str = "project.devprune.json";
676
677/// The adapter name the declared-directory pass answers to.
678///
679/// Not a package manager and not in `get_all_adapters()`, but it appears in the same
680/// column of the same report, so it needs the same kind of name — and `--only`,
681/// `--skip` and `disabled_adapters` all match on that column. Naming it here is what
682/// keeps the filter, the engine and the report agreeing on the spelling.
683pub const DECLARED_ADAPTER_NAME: &str = "declared";
684
685/// Public URL for the JSON Schema used by IDEs for .devprune.json IntelliSense.
686pub const JSON_SCHEMA_URL: &str = "https://devprune.vkrishna04.me/schemas/v1/devprune.schema.json";
687
688/// Directory under the user's home that marks a Claude Code installation.
689///
690/// Its presence is how the setup pass decides the machine has an agent to install the
691/// skill for; the directory itself is only ever created by Claude Code.
692pub const CLAUDE_HOME_DIR: &str = ".claude";
693
694/// Subdirectory of an agent's home where Agent Skills live, one directory per skill.
695pub const AGENT_SKILLS_SUBDIR: &str = "skills";
696
697/// Marketplace identifier (`publisher.name`) of the VS Code extension, as understood
698/// by `code --install-extension`.
699pub const VSCODE_EXTENSION_ID: &str = "VKrishna04.dev-prune";
700
701/// The WinGet package identifier, as published in `packaging/winget/` and in the
702/// manifests submitted to microsoft/winget-pkgs. `devp update` and `devp uninstall` name
703/// it back to the user, so a typo here sends someone to a command that does not resolve.
704pub const WINGET_PACKAGE_ID: &str = "VKrishna04.dev-prune";
705
706/// The Homebrew tap that carries the formula, as `brew tap` takes it. Not homebrew-core:
707/// plain `brew install dev-prune` resolves there, and that has a notability bar this
708/// project has not cleared. See `docs/DISTRIBUTION.md`.
709pub const HOMEBREW_TAP: &str = "Life-Experimentalist/tap";
710
711/// The Scoop bucket name and the repository behind it. `scoop bucket add` takes both,
712/// and the name is what `scoop install` then resolves `dev-prune` against.
713pub const SCOOP_BUCKET_NAME: &str = "life-experimentalist";
714/// Repository URL for [`SCOOP_BUCKET_NAME`].
715pub const SCOOP_BUCKET_URL: &str = "https://github.com/Life-Experimentalist/scoop-bucket";
716
717/// Where a person can read about the extension before installing it.
718///
719/// The offer prints all three. The two registries carry the same build — the release
720/// `.vsix` — but a machine that trusts one may not have the other, and someone who
721/// wants to read the source before letting anything into their editor needs neither.
722pub const VSCODE_MARKETPLACE_URL: &str =
723    "https://marketplace.visualstudio.com/items?itemName=VKrishna04.dev-prune";
724/// The Open VSX listing, which is what VSCodium, Cursor and Windsurf resolve against.
725pub const OPENVSX_URL: &str = "https://open-vsx.org/extension/VKrishna04/dev-prune";
726
727/// Name of the Windows Task Scheduler task the daemon registers.
728pub const WINDOWS_TASK_NAME: &str = "DevPrune";
729/// File name of the windowless scheduler binary — the same CLI built for the GUI
730/// subsystem, the relationship `pythonw.exe` has to `python.exe`. A `[[bin]]` target, so
731/// it ships in the Windows archives and `cargo install` places it; nothing generates it
732/// on a user's machine.
733pub const WINDOWS_WINDOWLESS_BIN: &str = "devpw.exe";
734/// Marker file (in the config directory) recording that this machine's Task Scheduler
735/// refused the sessionless (S4U) task registration, so setup keeps the console task
736/// instead of retrying the upgrade on every pass.
737///
738/// Named for what the task *is* and not for what it is not: this value lands in the
739/// binary's string table a few bytes from `devpw.exe`, and "devpw" next to "hidden" is
740/// what a reviewer running `strings` reads first. Nothing here is concealed from
741/// anyone — the task is listed in Task Scheduler under its own name and the marker is
742/// an empty file in the config directory — so the vocabulary must not imply otherwise.
743pub const SCHEDULER_WINDOWLESS_REFUSED_MARKER: &str = "scheduler-windowless-refused";
744
745/// Label of the macOS LaunchAgent the daemon registers (also names its plist file).
746pub const MACOS_LAUNCHD_LABEL: &str = "com.devprune.daemon";
747
748/// Where `devp skill --agent cursor` writes the per-repository rules.
749pub const CURSOR_RULES_FILE: &str = ".cursor/rules/dev-prune.mdc";
750
751/// Where `devp skill --agent windsurf` writes the per-repository rules.
752pub const WINDSURF_RULES_FILE: &str = ".windsurf/rules/dev-prune.md";
753
754/// Where `devp skill --agent antigravity` writes the per-repository rules —
755/// Antigravity (Google) reads workspace rules from `.agent/rules/`.
756pub const ANTIGRAVITY_RULES_FILE: &str = ".agent/rules/dev-prune.md";
757
758/// Where `devp skill --agent cline` writes its rules (Cline reads every file in the
759/// `.clinerules/` directory).
760pub const CLINE_RULES_FILE: &str = ".clinerules/dev-prune.md";
761
762/// Where `devp skill --agent agents-md` writes its marked block — the cross-tool
763/// convention read by Codex, Jules, Amp, Antigravity and others.
764pub const AGENTS_MD_FILE: &str = "AGENTS.md";
765
766/// Where `devp skill --agent roo` writes its rules (Roo Code reads every file in
767/// `.roo/rules/`).
768pub const ROO_RULES_FILE: &str = ".roo/rules/dev-prune.md";
769
770/// Where `devp skill --agent kilocode` writes its rules (Kilo Code reads every file in
771/// `.kilocode/rules/`).
772pub const KILOCODE_RULES_FILE: &str = ".kilocode/rules/dev-prune.md";
773
774/// Where `devp skill --agent continue` writes its rules (Continue reads every file in
775/// `.continue/rules/`).
776pub const CONTINUE_RULES_FILE: &str = ".continue/rules/dev-prune.md";
777
778/// Where `devp skill --agent amazon-q` writes its rules (Amazon Q Developer reads every
779/// file in `.amazonq/rules/`).
780pub const AMAZON_Q_RULES_FILE: &str = ".amazonq/rules/dev-prune.md";
781
782/// Where `devp skill --agent kiro` writes its rules (Kiro reads every file in
783/// `.kiro/steering/`).
784pub const KIRO_STEERING_FILE: &str = ".kiro/steering/dev-prune.md";
785
786/// Where `devp skill --agent trae` writes its rules (Trae reads every file in
787/// `.trae/rules/`).
788pub const TRAE_RULES_FILE: &str = ".trae/rules/dev-prune.md";
789
790/// The shared file `devp skill --agent junie` owns a marked block inside — JetBrains
791/// Junie reads one guidelines file, not a directory.
792pub const JUNIE_GUIDELINES_FILE: &str = ".junie/guidelines.md";
793
794/// The shared file `devp skill --agent gemini` owns a marked block inside — the Gemini
795/// CLI reads one context file per repository.
796pub const GEMINI_MD_FILE: &str = "GEMINI.md";
797
798/// The shared file `devp skill --agent zed` owns a marked block inside. Zed reads
799/// `.rules` ahead of every other convention, so a repository that also has an
800/// `AGENTS.md` still needs this one.
801pub const ZED_RULES_FILE: &str = ".rules";
802
803/// The shared file `devp skill --agent aider` owns a marked block inside. Aider is the
804/// one target that does not read its file on its own: `CONVENTIONS.md` is loaded only
805/// by `aider --read CONVENTIONS.md` or a `read: CONVENTIONS.md` line in
806/// `.aider.conf.yml`, which is why writing it prints that instruction.
807pub const AIDER_CONVENTIONS_FILE: &str = "CONVENTIONS.md";
808
809/// The shared file `devp skill --agent copilot` owns a marked block inside.
810pub const COPILOT_INSTRUCTIONS_FILE: &str = ".github/copilot-instructions.md";
811
812/// Markers around the block in [`COPILOT_INSTRUCTIONS_FILE`] that dev-prune manages.
813/// Everything outside them belongs to the user and is never touched.
814pub const RULES_BLOCK_START: &str = "<!-- dev-prune:rules:start -->";
815pub const RULES_BLOCK_END: &str = "<!-- dev-prune:rules:end -->";
816
817/// The phrase Git uses when it refuses a working tree owned by another account.
818///
819/// Matched against Git's own stderr rather than parsed: the message is twelve lines
820/// long, ten of which are identical for every repository refused, and `devp run`
821/// groups every repository sharing this cause under one explanation and one fix
822/// instead of reprinting those ten lines per repository.
823pub const GIT_DUBIOUS_OWNERSHIP: &str = "detected dubious ownership";
824
825/// The phrase Git uses when the path it was pointed at is not a working tree at all.
826///
827/// Same reasoning as [`GIT_DUBIOUS_OWNERSHIP`]: one cause, one fix, one paragraph.
828pub const GIT_NOT_A_REPOSITORY: &str = "not a git repository";