mrly.net

Dependencies

CLAUDE.md says prefer writing from scratch and hide what can't be. This is the line that decides cases.

Hand-roll when all three hold

decades. Code against a dead spec is finished forever; it has no maintenance tail.

Json is one enum and a parser, png writes stored deflate, chacha is one stream. A slice that grows features the kernel does not need has become a library, and libraries are what dependencies are for.

serde_json's exact bytes were load-bearing for byte-identity; upstream churn there is corruption. It is real: serde_json 1.0.151 quietly swapped ryu for zmij.

Rent when any holds

ours.

cpal stay dependencies, frozen. Own the face, rent the platform.

Our chacha exists for reproducibility, not secrecy.

The method

Nothing is deleted until its replacement is proven byte-identical against it: chacha differential-tested against rand 0.8, Json against serde_json over all 46 goldens. No proof, no deletion.