update clvmr to 1.17.5 - #440
prozacchiwawa wants to merge 3 commits into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. It is recommended to resolve "Warn" alerts too. Learn more about Socket for GitHub.
Ignoring alerts on:
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
Autofix Details
Bugbot Autofix prepared a fix for the issue found in the latest run.
- ✅ Fixed:
OriginalDialect::flags()panics withtodo!()at runtime- Replaced the
todo!()implementation ofOriginalDialect::flags()withself.flags, eliminating the runtime panic during operator dispatch.
- Replaced the
Or push these changes by commenting:
@cursor push 6a72fd6f82
Preview (6a72fd6f82)
diff --git a/src/classic/clvm_tools/stages/stage_0.rs b/src/classic/clvm_tools/stages/stage_0.rs
--- a/src/classic/clvm_tools/stages/stage_0.rs
+++ b/src/classic/clvm_tools/stages/stage_0.rs
@@ -164,7 +164,7 @@
}
fn flags(&self) -> ClvmFlags {
- todo!();
+ self.flags
}
fn gc_candidate(&self, _allocator: &Allocator, _node: NodePtr) -> bool {This Bugbot Autofix run was free. To enable autofix for future PRs, go to the Cursor dashboard.
|
@SocketSecurity ignore cargo/libm@0.2.16 |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 5cd9d9a. Configure here.
| uses: actions-rs/toolchain@v1 | ||
| with: | ||
| toolchain: stable | ||
| toolchain: 1.94.1 |
There was a problem hiding this comment.
CI uses wrong Rust toolchain for fmt and clippy
Medium Severity
The toolchain setup steps were changed from stable to 1.94.1, but the cargo +stable commands on lines 44 and 46 still reference the stable toolchain. Since stable is no longer explicitly installed by the action, these commands will either fail or silently use a pre-installed stable toolchain on the GitHub runner that differs from the intended version 1.94.1, defeating the purpose of pinning the toolchain.
Reviewed by Cursor Bugbot for commit 5cd9d9a. Configure here.



Note
Medium Risk
Updates a core execution dependency (
clvmr) and adapts dialect/flag handling, which could subtly change CLVM evaluation behavior across operator versions. Also pins CI/toolchains, so build failures are possible if the repo relied on newerstablebehavior.Overview
Upgrades the
clvmrdependency to0.17.5(including lockfile updates for new/transitive crates) for both the main crate and the WASM build.Refactors classic runner/dialect integration to match
clvmr’s newClvmFlagsAPI: introduceschoose_run_flags, stores flags onCompilerOperatorsInternal, threads flags through dialect ops, and ensures flags are restored after nestedrun_programcalls.Pins Rust toolchains to
1.94.1acrossrust-toolchain.toml,wasm/rust-toolchain.toml, and GitHub Actions workflows to keep builds consistent.Reviewed by Cursor Bugbot for commit 5cd9d9a. Bugbot is set up for automated code reviews on this repo. Configure here.