Money without floating point
Every amount is a Decimal in the core and integer cents in the frontend. A property-based suite plus 1:1 Rust↔TS contract tests keep both implementations identical; float arithmetic is banned by rule and by test.
Engineering case study
DatioLabs Retail is a Windows desktop POS for Venezuelan retail: it operates fully offline, handles USD/VES money with exact decimal arithmetic, and keeps every record on the client's machine. This page is the engineering view: how it is built and how it is verified.
Retail shops in Venezuela run on modest Windows PCs with unreliable connectivity. Prices are anchored in USD while customers pay in bolivars at the official BCV rate, which changes daily. Software that assumes a server, an internet connection or a subscription is not an option: the shop must keep selling when the network is down, and the data must stay on the shop's machine.
Three layers with one deliberate boundary: the interface never touches storage directly.
Every amount is a Decimal in the core and integer cents in the frontend. A property-based suite plus 1:1 Rust↔TS contract tests keep both implementations identical; float arithmetic is banned by rule and by test.
Records are stored with positional bincode. Adding, removing or reordering a field would corrupt every existing client database, so persisted structs are frozen and new features get new trees. Backups stay cross-version by construction.
Stock changes only through movements. Perishables rotate FEFO; packaging (packs, boxes, fractions) discounts stock atomically; oversell is rejected and five concurrent sales leave the stock exact.
Business types and features are encoded as u16 bitmasks: grocery, bakery, liquor and retail capabilities combine in a single build with no forked UI.
A BCV scraper keeps the official rate fresh, freezes it per transaction line, and falls back to a cached value when there is no connectivity. Manual mode is sticky and always wins.
License keys are validated by exact match against a canonical list mirrored in four places with checksums; a forged key stops the app. Operations are signed (SHA-256) and annulments keep a dedicated ledger.
Three layers, from unit tests to a remote harness that clicks the real desktop application.
64 Rust tests in the core plus 5 in the desktop shell, and 96 frontend tests across 9 suites. The frontend/backend money contract is enforced by 1:1 contract tests. Rust core coverage: 95.15% of lines (92.59% of functions, 91.13% of regions, measured with cargo-llvm-cov).
proptest in Rust and fast-check in TypeScript attack the money and inventory invariants with randomized cases; two cargo-fuzz targets (full_system_fuzz, ingest_fuzz) fuzz the domain and the rate ingestion paths.
No mocks: a test build of the Tauri app exposes the Chrome DevTools Protocol and Playwright-core drives real clicks on the real WebView2. The harness runs from a Linux workstation over SSH/SCP against a Windows Server, with an isolated APPDATA and a scheduled interactive task. The test binary and the debug flag never reach the installer — verified in the final artifact.
| Rust core tests | 64 all green |
|---|---|
| Desktop shell tests (Windows) | 5 |
| Frontend tests | 96 · 9 suites · 7.3 s |
| Rust core line coverage | 95.15% |
| E2E scenarios | 107 · matrices A–N |
| E2E scripts (CDP + Playwright) | 27 |
| Tauri command coverage | 69 / 69 |
| Persistence trees | 15 |
| Signed installer | 3,256,020 bytes · 3.1 MB |
| E2E test binary (never shipped) | 10,462,208 bytes · 10.0 MB |
| Source size | Rust 7,254 LOC · TypeScript 13,932 LOC (+2,134 tests) |
Method: measured on 2026-09-30 — cargo test (core and shell), vitest run, cargo llvm-cov -p datiolabs-core, artifact sizes, scenario counting from e2e/ESCENARIOS.md. Only numbers that can be reproduced with a documented command are published.
Real screenshots of the running application (web demo, mock backend).
Phases 1–4 are implemented, verified and packaged (2026-09-19): product, offline rate, multi-vertical capabilities and the verification stack. The desktop application is licensed and distributed directly; this page is the engineering view, not the storefront.