Verify managed installs against release checksums, serialize them with
a cross-process lock, and record the compiler identity that produced
the Move graph so a compiler change forces a full rebuild. Fail closed
when the existing Move graph needs a compiler that is unavailable.
Replace the npm-postinstall installer (scripts/install-move-flow.cjs)
with analyze-time provisioning: resolve $MOVE_FLOW, then a verified
user cache under ~/.gitnexus/tools/move-flow, then $PATH, then a
one-time download of the pinned release verified against SHA256SUMS.
Installs are serialized across processes via a lease/heartbeat lock
and staged into place atomically.
- Gate the client probe on the pinned release major (prerelease
suffixes accepted); drop the legacy vendor/move-flow bundled path.
- Honor GITNEXUS_SKIP_MOVE_FLOW and GITNEXUS_SKIP_OPTIONAL_GRAMMARS;
do not retry a failed install within the same process.
- Consolidate node-table DDL, CSV headers, row encoding, and COPY
column lists into lbug/node-table-layout.ts (replaces
move-columns.ts); align boolean CSV encoding with the incremental
CREATE path.
- CI: cache ~/.gitnexus/tools/move-flow keyed to the pinned version;
require provisioning on the shard that owns the live Move suite.
- Docker: install unzip for on-demand extraction; the image no longer
ships a move-flow binary.