Add CLDC 1.1 core API compatibility - #177
Conversation
There was a problem hiding this comment.
💡 Codex Review
When both Class objects are arrays, this falls back to inheritance only. Array class definitions report Object as the superclass and no interfaces, so cases such as Object[].class.isAssignableFrom(String[].class) or Cloneable.class.isAssignableFrom(String[].class) return false even though the JVM's normal type checks already support array covariance and array supertypes. Reflection-based type checks over arrays will therefore reject valid assignments; this should use the same type-assignability path as isInstance rather than is_inherited_from.
When the decoder withholds an incomplete multibyte sequence and no characters are buffered yet, for example a UTF-8 stream whose read returns only the first byte of a 3-byte character, writeBufSize stays 0 and this returns 0 even though length > 0. Reader.read(char[], off, len) is only allowed to return 0 for zero-length requests, so callers that loop until EOF or positive progress can spin on split/truncated multibyte input. Keep reading until a character, EOF/replacement, or an exception is available before returning.
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
Pull request overview
This PR extends the RustJava runtime toward CLDC 1.1 core API compatibility, adding missing class hierarchies and filling in key java.io, java.lang, and java.util behaviors so CLDC-era code can run with closer-to-spec semantics.
Changes:
- Adds/extends CLDC 1.1 core library surface area (exceptions/errors,
Class,Thread,Throwable,Random,Vector,Hashtable, date/calendar/time zone). - Completes important
java.iostream/reader/writer/data stream behavior (including modified UTF and charset handling). - Expands test coverage for the added CLDC contracts across
java.lang,java.util, andjava.io.
Reviewed changes
Copilot reviewed 61 out of 61 changed files in this pull request and generated 4 comments.
Show a summary per file
| File | Description |
|---|---|
| jvm/src/jvm.rs | Bootstrap loads Runnable; thread count API |
| java_runtime/src/loader.rs | Registers newly added runtime classes |
| java_runtime/src/classes/java/util/vector.rs | Adds CLDC Vector legacy APIs |
| java_runtime/src/classes/java/util/time_zone.rs | Adds TimeZone ID/default/available IDs |
| java_runtime/src/classes/java/util/simple_time_zone.rs | Implements raw offset and validations |
| java_runtime/src/classes/java/util/random.rs | Implements CLDC Random algorithms/APIs |
| java_runtime/src/classes/java/util/hashtable.rs | Adds legacy Hashtable APIs + toString/rehash |
| java_runtime/src/classes/java/util/gregorian_calendar.rs | Time/timezone handling and field validation |
| java_runtime/src/classes/java/util/empty_stack_exception.rs | Corrects EmptyStackException name/package |
| java_runtime/src/classes/java/util/date.rs | Implements Date equals/hashCode/toString |
| java_runtime/src/classes/java/util/calendar.rs | Adds millis/timezone and comparison APIs |
| java_runtime/src/classes/java/net/url_connection.rs | Fixes UnknownServiceException package |
| java_runtime/src/classes/java/net/unknown_service_exception.rs | Corrects UnknownServiceException name/package |
| java_runtime/src/classes/java/lang/virtual_machine_error.rs | Adds VirtualMachineError base type |
| java_runtime/src/classes/java/lang/out_of_memory_error.rs | Adds OutOfMemoryError under VME |
| java_runtime/src/classes/java/lang/instantiation_exception.rs | Adds InstantiationException class |
| java_runtime/src/classes/java/lang/illegal_thread_state_exception.rs | Adds IllegalThreadStateException class |
| java_runtime/src/classes/java/lang/illegal_monitor_state_exception.rs | Adds IllegalMonitorStateException class |
| java_runtime/src/classes/java/lang/illegal_access_exception.rs | Adds IllegalAccessException class |
| java_runtime/src/classes/java/lang/throwable.rs | Adds Throwable.getMessage |
| java_runtime/src/classes/java/lang/thread.rs | Adds CLDC Thread metadata/state APIs |
| java_runtime/src/classes/java/lang/class.rs | Adds CLDC Class query/newInstance/toString |
| java_runtime/src/classes/java/lang.rs | Exports and wires new lang classes |
| java_runtime/src/classes/java/io/writer.rs | Aligns Writer API to CLDC/JDK contracts |
| java_runtime/src/classes/java/io/reader.rs | Aligns Reader API + skip/mark defaults |
| java_runtime/src/classes/java/io/print_writer.rs | Updates PrintWriter write/flush/close signatures |
| java_runtime/src/classes/java/io/print_stream.rs | Implements broader PrintStream contract |
| java_runtime/src/classes/java/io/output_stream_writer.rs | Adds OutputStreamWriter with charset handling |
| java_runtime/src/classes/java/io/interrupted_io_exception.rs | Adds InterruptedIOException + field |
| java_runtime/src/classes/java/io/input_stream.rs | Implements InputStream read/available/close defaults |
| java_runtime/src/classes/java/io/input_stream_reader.rs | Charset ctor + split multibyte handling |
| java_runtime/src/classes/java/io/filter_output_stream.rs | Adds flush/close forwarding |
| java_runtime/src/classes/java/io/filter_input_stream.rs | Adds skip/mark/markSupported forwarding |
| java_runtime/src/classes/java/io/data_output.rs | Expands DataOutput interface surface |
| java_runtime/src/classes/java/io/data_output_stream.rs | Implements CLDC primitive + modified UTF writes |
| java_runtime/src/classes/java/io/data_input.rs | Adds readUnsignedByte requirement |
| java_runtime/src/classes/java/io/data_input_stream.rs | Implements required reads + modified UTF decoding |
| java_runtime/src/classes/java/io/byte_array_output_stream.rs | Adds write([BII), toString, size validation |
| java_runtime/src/classes/java/io/byte_array_input_stream.rs | Adds bounds checks + markSupported |
| java_runtime/src/classes/java/io/string_writer.rs | Updates write signature; adds flush/close |
| java_runtime/src/classes/java/io/unsupported_encoding_exception.rs | Adds UnsupportedEncodingException |
| java_runtime/src/classes/java/io/utf_data_format_exception.rs | Adds UTFDataFormatException |
| java_runtime/src/classes/java/io.rs | Wires new java.io classes |
| java_runtime/tests/classes/java/util/test_vector.rs | Adds Vector CLDC legacy API test |
| java_runtime/tests/classes/java/util/test_timezone.rs | Expands TimeZone behavior tests |
| java_runtime/tests/classes/java/util/test_random.rs | Adds CLDC Random algorithm tests |
| java_runtime/tests/classes/java/util/test_hashtable.rs | Adds Hashtable legacy API tests |
| java_runtime/tests/classes/java/util/test_gregorian_calendar.rs | Adds Calendar time/comparison API tests |
| java_runtime/tests/classes/java/util/test_date.rs | Adds Date CLDC value contract test |
| java_runtime/tests/classes/java/util/mod.rs | Registers new util tests |
| java_runtime/tests/classes/java/lang/test_throwable.rs | Adds getMessage coverage |
| java_runtime/tests/classes/java/lang/test_thread.rs | Adds CLDC Thread metadata/state test |
| java_runtime/tests/classes/java/lang/test_cldc11_exceptions.rs | Adds CLDC exception hierarchy tests |
| java_runtime/tests/classes/java/lang/test_class.rs | Adds CLDC Class query/newInstance tests |
| java_runtime/tests/classes/java/lang/mod.rs | Registers new lang tests |
| java_runtime/tests/classes/java/io/test_string_writer.rs | Updates Writer signature expectations |
| java_runtime/tests/classes/java/io/test_print_stream.rs | Adds PrintStream CLDC API tests |
| java_runtime/tests/classes/java/io/test_output_stream_writer.rs | Adds OutputStreamWriter encoding/surrogate tests |
| java_runtime/tests/classes/java/io/test_input_stream_reader.rs | Adds ISR split multibyte/encoding tests |
| java_runtime/tests/classes/java/io/test_data_output_stream.rs | Adds CLDC data stream round-trip tests |
| java_runtime/tests/classes/java/io/mod.rs | Registers new io tests |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
dlunch
commented
Jul 16, 2026
Addressed the remaining actionable review findings in ad52cbc:
Verified with cargo test --workspace and stable/beta Clippy with warnings denied. The four Vector/modified UTF-8 threads were answered and resolved as JDK-compatible behavior. |
Uh oh!
There was an error while loading. Please reload this page.
Judged the two remaining remote branches on the fork: - dependabot/cargo/tracing-attributes-0.1.31: deleted. PR #4 (fa92ef9) removed the tracing-attributes direct dependency outright, so the branch patches a Cargo.toml line that no longer exists. - wie-ktf-hardening: preserved. 8 of its 12 commits are already in upstream/main via squash merges (dlunch#174dlunch#175dlunch#176dlunch#177dlunch#180dlunch#182); git cherry missed this because origin/main trails upstream/main by 20 commits. 4 commits carry residual value. No code changes. Co-authored-by: jun0 <junyoung.choi.a@miraeasset.com> Co-authored-by: Claude <noreply@anthropic.com>
…am-sync-s2] * Bump bytemuck from 1.25.0 to 1.25.1 (dlunch#173) Bumps [bytemuck](https://github.com/Lokathor/bytemuck) from 1.25.0 to 1.25.1. - [Changelog](https://github.com/Lokathor/bytemuck/blob/main/changelog.md) - [Commits](Lokathor/bytemuck@v1.25.0...v1.25.1) --- updated-dependencies: - dependency-name: bytemuck dependency-version: 1.25.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Replace runtime panics with the matching Java exceptions (dlunch#174) * Replace runtime panics with the matching Java exceptions An unwrap audit found panics reachable from ordinary Java code: - File.length() returns 0 for a missing file; isDirectory/isFile lose their guard-then-unwrap shape - FileImpl (native runtime) maps open/read/write/seek failures to IOError instead of panicking, so FileInputStream and RandomAccessFile guards actually produce FileNotFoundException; FileOutputStream gains the same guard - File I/O operations (read/write/seek/available/length/setLength) throw java.io.IOException on failure via a shared helper - Class.forName resolves the class and throws ClassNotFoundException (new runtime class) instead of panicking on any not-yet-loaded name - StringBuffer.append(char)/append(char[]) keep exact UTF-16 units so unpaired surrogates no longer panic and pairs built char by char survive; String.valueOf(char) builds through [C for the same reason - PrintStream.println(char) replaces an unpaired surrogate with '?' like the JDK charset encoder - ZipFile validates the archive in its constructor and throws java.util.zip.ZipException (new runtime class) for a malformed archive; getInputStream returns null for a missing entry Expected outputs for the new fixtures are generated by a real JVM. Remaining unwraps are invariants (interpreter stack discipline, thread attach), guarded lookups, or documented gaps (lenient calendar normalization, ClassFormatError plumbing). * Inline the IOException conversion at each I/O call site * Return the same Thread object from Thread.currentThread() (dlunch#175) Every attached thread now owns its java/lang/Thread instance: attach takes the instance for threads started via Thread.start (so currentThread() inside run() is the started Thread object) and creates one otherwise (bootstrap, external attachers). currentThread() returns the stored instance, and the GC roots it per thread. Also parse unrecognized classfile attributes as an opaque Unknown variant instead of failing — JVMS 4.7.1 requires silently ignoring them, and the anonymous-class fixture carries EnclosingMethod and Signature attributes the parser rejected. Expected output for the fixture is generated by a real JVM. * Add Java primitive wrapper classes (dlunch#176) * Add Java primitive wrapper classes * Use Character digit semantics for numeric parsing * Bump tokio from 1.52.3 to 1.52.4 (dlunch#179) Bumps [tokio](https://github.com/tokio-rs/tokio) from 1.52.3 to 1.52.4. - [Release notes](https://github.com/tokio-rs/tokio/releases) - [Commits](tokio-rs/tokio@tokio-1.52.3...tokio-1.52.4) --- updated-dependencies: - dependency-name: tokio dependency-version: 1.52.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Add CLDC 1.1 core API compatibility (dlunch#177) * Add CLDC 1.1 core API compatibility * Fix CI lint and improve CLDC coverage * Fix array assignability and reader progress * [rustjava-upstream-sync-s2] docs: record S2 landing (cut af4f6f8, conflicts 5, ancestry restore) --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Inseok Lee <git@dlun.ch> Co-authored-by: jun0 <junyoung.choi.a@miraeasset.com>
…m-sync-s3] * Bump bytemuck from 1.25.0 to 1.25.1 (dlunch#173) Bumps [bytemuck](https://github.com/Lokathor/bytemuck) from 1.25.0 to 1.25.1. - [Changelog](https://github.com/Lokathor/bytemuck/blob/main/changelog.md) - [Commits](Lokathor/bytemuck@v1.25.0...v1.25.1) --- updated-dependencies: - dependency-name: bytemuck dependency-version: 1.25.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Replace runtime panics with the matching Java exceptions (dlunch#174) * Replace runtime panics with the matching Java exceptions An unwrap audit found panics reachable from ordinary Java code: - File.length() returns 0 for a missing file; isDirectory/isFile lose their guard-then-unwrap shape - FileImpl (native runtime) maps open/read/write/seek failures to IOError instead of panicking, so FileInputStream and RandomAccessFile guards actually produce FileNotFoundException; FileOutputStream gains the same guard - File I/O operations (read/write/seek/available/length/setLength) throw java.io.IOException on failure via a shared helper - Class.forName resolves the class and throws ClassNotFoundException (new runtime class) instead of panicking on any not-yet-loaded name - StringBuffer.append(char)/append(char[]) keep exact UTF-16 units so unpaired surrogates no longer panic and pairs built char by char survive; String.valueOf(char) builds through [C for the same reason - PrintStream.println(char) replaces an unpaired surrogate with '?' like the JDK charset encoder - ZipFile validates the archive in its constructor and throws java.util.zip.ZipException (new runtime class) for a malformed archive; getInputStream returns null for a missing entry Expected outputs for the new fixtures are generated by a real JVM. Remaining unwraps are invariants (interpreter stack discipline, thread attach), guarded lookups, or documented gaps (lenient calendar normalization, ClassFormatError plumbing). * Inline the IOException conversion at each I/O call site * Return the same Thread object from Thread.currentThread() (dlunch#175) Every attached thread now owns its java/lang/Thread instance: attach takes the instance for threads started via Thread.start (so currentThread() inside run() is the started Thread object) and creates one otherwise (bootstrap, external attachers). currentThread() returns the stored instance, and the GC roots it per thread. Also parse unrecognized classfile attributes as an opaque Unknown variant instead of failing — JVMS 4.7.1 requires silently ignoring them, and the anonymous-class fixture carries EnclosingMethod and Signature attributes the parser rejected. Expected output for the fixture is generated by a real JVM. * Add Java primitive wrapper classes (dlunch#176) * Add Java primitive wrapper classes * Use Character digit semantics for numeric parsing * Bump tokio from 1.52.3 to 1.52.4 (dlunch#179) Bumps [tokio](https://github.com/tokio-rs/tokio) from 1.52.3 to 1.52.4. - [Release notes](https://github.com/tokio-rs/tokio/releases) - [Commits](tokio-rs/tokio@tokio-1.52.3...tokio-1.52.4) --- updated-dependencies: - dependency-name: tokio dependency-version: 1.52.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Add CLDC 1.1 core API compatibility (dlunch#177) * Add CLDC 1.1 core API compatibility * Fix CI lint and improve CLDC coverage * Fix array assignability and reader progress * Harden JVM runtime correctness (dlunch#180) * Harden JVM runtime correctness * Address classfile review findings * Move class initialization tests to Java fixture * Separate classfile validation from JVM verification * Remove ClassFileError re-export * [rustjava-upstream-sync-s2] docs: record S2 landing (cut af4f6f8, conflicts 5, ancestry restore) * [rustjava-upstream-sync-s3] docs: record S3 landing (cut 822504b, conflicts 11) + refresh STATE 「다음」 STATE.md ③-0 pointed at rustjava-pr8-claude-md-prune-disposition as top priority on the grounds that its review.md was missing and gate 2 had stalled. Both are false now: PR #8 is MERGED (2026-08-18T19:26:08Z -> 00bddf3) and the review reports exist. Item closed, list renumbered, ⑤ operating notes re-measured (open PRs 2 -> 1, dead branch row dropped). * [rustjava-upstream-sync-s3] docs: record S2 landing (11ef501) and correct the ancestry-axis prediction --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Inseok Lee <git@dlun.ch> Co-authored-by: jun0 <junyoung.choi.a@miraeasset.com>
* Bump bytemuck from 1.25.0 to 1.25.1 (dlunch#173) Bumps [bytemuck](https://github.com/Lokathor/bytemuck) from 1.25.0 to 1.25.1. - [Changelog](https://github.com/Lokathor/bytemuck/blob/main/changelog.md) - [Commits](Lokathor/bytemuck@v1.25.0...v1.25.1) --- updated-dependencies: - dependency-name: bytemuck dependency-version: 1.25.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Replace runtime panics with the matching Java exceptions (dlunch#174) * Replace runtime panics with the matching Java exceptions An unwrap audit found panics reachable from ordinary Java code: - File.length() returns 0 for a missing file; isDirectory/isFile lose their guard-then-unwrap shape - FileImpl (native runtime) maps open/read/write/seek failures to IOError instead of panicking, so FileInputStream and RandomAccessFile guards actually produce FileNotFoundException; FileOutputStream gains the same guard - File I/O operations (read/write/seek/available/length/setLength) throw java.io.IOException on failure via a shared helper - Class.forName resolves the class and throws ClassNotFoundException (new runtime class) instead of panicking on any not-yet-loaded name - StringBuffer.append(char)/append(char[]) keep exact UTF-16 units so unpaired surrogates no longer panic and pairs built char by char survive; String.valueOf(char) builds through [C for the same reason - PrintStream.println(char) replaces an unpaired surrogate with '?' like the JDK charset encoder - ZipFile validates the archive in its constructor and throws java.util.zip.ZipException (new runtime class) for a malformed archive; getInputStream returns null for a missing entry Expected outputs for the new fixtures are generated by a real JVM. Remaining unwraps are invariants (interpreter stack discipline, thread attach), guarded lookups, or documented gaps (lenient calendar normalization, ClassFormatError plumbing). * Inline the IOException conversion at each I/O call site * Return the same Thread object from Thread.currentThread() (dlunch#175) Every attached thread now owns its java/lang/Thread instance: attach takes the instance for threads started via Thread.start (so currentThread() inside run() is the started Thread object) and creates one otherwise (bootstrap, external attachers). currentThread() returns the stored instance, and the GC roots it per thread. Also parse unrecognized classfile attributes as an opaque Unknown variant instead of failing — JVMS 4.7.1 requires silently ignoring them, and the anonymous-class fixture carries EnclosingMethod and Signature attributes the parser rejected. Expected output for the fixture is generated by a real JVM. * Add Java primitive wrapper classes (dlunch#176) * Add Java primitive wrapper classes * Use Character digit semantics for numeric parsing * Bump tokio from 1.52.3 to 1.52.4 (dlunch#179) Bumps [tokio](https://github.com/tokio-rs/tokio) from 1.52.3 to 1.52.4. - [Release notes](https://github.com/tokio-rs/tokio/releases) - [Commits](tokio-rs/tokio@tokio-1.52.3...tokio-1.52.4) --- updated-dependencies: - dependency-name: tokio dependency-version: 1.52.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Add CLDC 1.1 core API compatibility (dlunch#177) * Add CLDC 1.1 core API compatibility * Fix CI lint and improve CLDC coverage * Fix array assignability and reader progress * Harden JVM runtime correctness (dlunch#180) * Harden JVM runtime correctness * Address classfile review findings * Move class initialization tests to Java fixture * Separate classfile validation from JVM verification * Remove ClassFileError re-export * Bump tokio from 1.52.4 to 1.53.0 (dlunch#181) Bumps [tokio](https://github.com/tokio-rs/tokio) from 1.52.4 to 1.53.0. - [Release notes](https://github.com/tokio-rs/tokio/releases) - [Commits](tokio-rs/tokio@tokio-1.52.4...tokio-1.53.0) --- updated-dependencies: - dependency-name: tokio dependency-version: 1.53.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Hide classfile errors behind class definition errors * Delegate null-parent class loading to bootstrap * Remove duplicate array instance methods * Add JNI-style global references (dlunch#182) * Generalize monitor instance arguments * Add CDC text formatting APIs (dlunch#183) * Add CDC text formatting APIs * Add integer number format factories * Fix text format position handling * Add CLI classpath options (dlunch#184) * Add CLI classpath options * Simplify URL classpath lookup * Fix platform classpath handling * Use File path separator for class loading * Separate RustJar class loading * [rustjava-upstream-sync-s4] test: widen test_timer_periodic margin 500ms->2000ms (upstream 3296139 slowed TimerThread) * [rustjava-upstream-sync-s4] docs: record S4 landing (cut 3296139, conflicts 20->2) + S3 landing sha * [rustjava-upstream-sync-s4] docs: correct the timer finding - chronic boundary test, not a cut regression The prior wording compared a standalone run on origin/main against parallel full-suite runs on upstream and called the gap a regression. Matched-condition alternating runs show no difference (standalone x10: pre 3.5 mean / post 3.5 mean; full-suite x8: no difference). Upstream widened this same margin in 895d67d (2025-08) and ad8b477 (2025-10), both already ancestors of main, 11 months before e557673 (2026-07) which the prior wording blamed. sleep 2000 and both conflict resolutions are untouched. Comment-only in .rs; no code change. * [rustjava-upstream-sync-s4] docs: retarget follow-up (4) - no timer perf regression exists; the open axis is our test's wall-clock dependence REPORT.md line 27 already said the 'imported upstream regression' framing was wrong, but the follow-up list 20 lines below still carried it verbatim - and that list is what the next round tickets from. Retargeted to the axis that does exist (our test design, no upstream sending). --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Inseok Lee <git@dlun.ch> Co-authored-by: jun0 <junyoung.choi.a@miraeasset.com>
Summary
java.iostream, reader/writer, data stream, charset, andPrintStreamcontractsClass,Thread,Throwable,Random,Vector,Hashtable, date, calendar, and time zone APIsCompatibility
RandomalgorithmValidation
cargo test --workspace(178 passed, 1 ignored)cargo clippy --workspace --all-targetscargo fmt --all -- --checkgit diff --check