Engineering case study

A local-first point of sale, written in Rust

DatioLabs Retail is a Windows desktop POS for Venezuelan retail: it operates fully offline, handles USD/VES money with exact decimal arithmetic, and keeps every record on the client's machine. This page is the engineering view: how it is built and how it is verified.

Open the live web demo Read the case study
165
automated tests
95.2%
Rust core line coverage
107
real E2E scenarios
3.1 MB
signed Windows installer

Context

Retail shops in Venezuela run on modest Windows PCs with unreliable connectivity. Prices are anchored in USD while customers pay in bolivars at the official BCV rate, which changes daily. Software that assumes a server, an internet connection or a subscription is not an option: the shop must keep selling when the network is down, and the data must stay on the shop's machine.

Architecture

Three layers with one deliberate boundary: the interface never touches storage directly.

Frontend SPATypeScript · Vite · Tailwind
Tauri IPCin-process, no network
datiolabs-coreRust domain engine
Sledembedded DB · SHA-256 signed

Engineering decisions

Money without floating point

Every amount is a Decimal in the core and integer cents in the frontend. A property-based suite plus 1:1 Rust↔TS contract tests keep both implementations identical; float arithmetic is banned by rule and by test.

A schema you cannot break

Records are stored with positional bincode. Adding, removing or reordering a field would corrupt every existing client database, so persisted structs are frozen and new features get new trees. Backups stay cross-version by construction.

Inventory as an atomic ledger

Stock changes only through movements. Perishables rotate FEFO; packaging (packs, boxes, fractions) discounts stock atomically; oversell is rejected and five concurrent sales leave the stock exact.

One binary, several verticals

Business types and features are encoded as u16 bitmasks: grocery, bakery, liquor and retail capabilities combine in a single build with no forked UI.

The exchange rate, offline

A BCV scraper keeps the official rate fresh, freezes it per transaction line, and falls back to a cached value when there is no connectivity. Manual mode is sticky and always wins.

Licensing and audit you can verify

License keys are validated by exact match against a canonical list mirrored in four places with checksums; a forged key stops the app. Operations are signed (SHA-256) and annulments keep a dedicated ledger.

Verification

Three layers, from unit tests to a remote harness that clicks the real desktop application.

L1 Unit & contract

64 Rust tests in the core plus 5 in the desktop shell, and 96 frontend tests across 9 suites. The frontend/backend money contract is enforced by 1:1 contract tests. Rust core coverage: 95.15% of lines (92.59% of functions, 91.13% of regions, measured with cargo-llvm-cov).

L2 Property & fuzz

proptest in Rust and fast-check in TypeScript attack the money and inventory invariants with randomized cases; two cargo-fuzz targets (full_system_fuzz, ingest_fuzz) fuzz the domain and the rate ingestion paths.

L3 Real E2E over CDP

No mocks: a test build of the Tauri app exposes the Chrome DevTools Protocol and Playwright-core drives real clicks on the real WebView2. The harness runs from a Linux workstation over SSH/SCP against a Windows Server, with an isolated APPDATA and a scheduled interactive task. The test binary and the debug flag never reach the installer — verified in the final artifact.

Linux workstation -- scp/ssh --> Windows Server -- CDP :9222 --> Real Tauri app (WebView2)

By the numbers

Rust core tests64 all green
Desktop shell tests (Windows)5
Frontend tests96 · 9 suites · 7.3 s
Rust core line coverage95.15%
E2E scenarios107 · matrices A–N
E2E scripts (CDP + Playwright)27
Tauri command coverage69 / 69
Persistence trees15
Signed installer3,256,020 bytes · 3.1 MB
E2E test binary (never shipped)10,462,208 bytes · 10.0 MB
Source sizeRust 7,254 LOC · TypeScript 13,932 LOC (+2,134 tests)

Method: measured on 2026-09-30 — cargo test (core and shell), vitest run, cargo llvm-cov -p datiolabs-core, artifact sizes, scenario counting from e2e/ESCENARIOS.md. Only numbers that can be reproduced with a documented command are published.

The product

Real screenshots of the running application (web demo, mock backend).

Status

Phases 1–4 are implemented, verified and packaged (2026-09-19): product, offline rate, multi-vertical capabilities and the verification stack. The desktop application is licensed and distributed directly; this page is the engineering view, not the storefront.