Skip to content
This repository was archived by the owner on Aug 7, 2026. It is now read-only.

fix: restore green CI — rustfmt, sibling API drift, clippy; canonicalize RP-CI-PARITY - #6

Merged
kpernyer merged 9 commits into
mainfrom
next
Jul 2, 2026
Merged

kpernyer merged 9 commits into
mainfrom
next

Conversation

@kpernyer

@kpernyer kpernyer commented Jul 2, 2026 •

Copy link
Copy Markdown
Contributor

Root causes fixed

  • CI (Format) red since 07-01: unformatted code in scenarios/helm-realtime-stem-headless — fixed with cargo fmt --all (own commit).
  • CI (Check) / Coverage red: helms origin/main added a third triggered_by: Option<FindingId> parameter to helm-client::formation_completed; the headless stem scenario still passed 2 args (E0061 in every fresh sibling checkout). Now passes None.
  • Lint (latent): 5 clippy -D warnings errors in the same scenario (private_interfaces, dead_code, collapsible_if) that would surface once Check passes — fixed.
  • Security (Audit) red: RUSTSEC-2026-0187 (lopdf 0.38, fix >=0.42) + RUSTSEC-2026-0192 (ttf-parser unmaintained). Both pinned transitively via pdf-extract 0.10 → organism-intelligence; no fixed version reachable, so both added to the blocking-audit ignore lists with a dated comment (script + Justfile kept in sync). memmap2 RUSTSEC-2026-0186 resolves to 0.9.11 on fresh locks (Cargo.lock is gitignored in this repo).

Canonicalization (RP-CI-PARITY)

  • Justfile: new ci: fmt-check check lint test aggregate with canonical flags; check gains --all-targets; lint is clippy-only; release-check runs fmt-check explicitly; all other recipes preserved.
  • ci.yml: check/test/lint/format jobs collapsed into a single just ci job; sibling checkout + protobuf setup steps preserved; solver E2E job untouched.

Verification (local, full sibling workspace)

  • cargo fmt --all -- --check ✓
  • cargo check --workspace --all-targets ✓
  • cargo clippy --workspace --all-targets -- -D warnings ✓
  • cargo test --workspace --all-targets ✓

🤖 Generated with Claude Code


Note

Low Risk
Mostly CI/docs and a scenario API fix; supply-chain ignores are explicit and documented, with limited exposure called out in comments.

Overview
Restores CI by aligning GitHub Actions with a single just ci job (fmt-check, check with --all-targets, clippy, test) under RP-CI-PARITY, replacing four parallel jobs while keeping sibling checkout and protobuf setup.

Fixes helm-realtime-stem-headless for upstream helm-client::formation_completed (third triggered_by argument, passed as None), plus rustfmt and clippy cleanups in that scenario.

Unblocks security audit by documenting and syncing new cargo-audit / cargo-deny ignores for transitive lopdf, ttf-parser, and quick-xml advisories across Justfile, scripts/ci/cargo-audit-blocking.sh, and deny.toml. release-check now runs fmt-check explicitly.

Docs: kb/Planning/MILESTONES.md marked archived (work in Linear); floor versions consolidated into AGENTS.md; CLAUDE.md trimmed accordingly.

Reviewed by Cursor Bugbot for commit 0121df7. Bugbot is set up for automated code reviews on this repo. Configure here.

kpernyer and others added 6 commits July 2, 2026 10:44
Fixes the Format job failure on main (cargo fmt --all -- --check diff
in helm-realtime-stem-headless).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
helm-client on helms origin/main added a third parameter
(triggered_by: Option<FindingId>) to formation_completed; the
headless stem scenario has no triggering finding, so pass None.
Restores cargo check against fresh sibling checkouts.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
- make ParticipantSlot/ServerLoopRecord pub (private_interfaces on the
  pub fields of RealtimeStemRun exposing them)
- make record fields pub, silencing dead_code on diagnostic fields
- collapse nested if into a let-chain (collapsible_if, edition 2024)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
lopdf 0.38 (stack overflow, fix >=0.42) and ttf-parser (unmaintained)
are pinned transitively via pdf-extract 0.10 -> organism-intelligence;
no fixed version is reachable until pdf-extract moves to lopdf >=0.42.
Cargo.lock is gitignored here so cargo update cannot be pinned in-repo;
memmap2 (RUSTSEC-2026-0186) already resolves to 0.9.11 on fresh locks.

Also canonicalizes the Justfile per RP-CI-PARITY:
- ci: fmt-check check lint test (new canonical aggregate)
- fmt-check: cargo fmt --all -- --check
- check gains --all-targets
- lint is clippy-only; release-check now runs fmt-check explicitly

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ITY)

ci.yml is now a thin runner around 'just ci'; sibling checkout and
protobuf setup steps preserved. Solver E2E job untouched.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@cursor

cursor Bot commented Jul 2, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_e0d71ee2-f517-4bdd-a02d-8580cdfa2b75)

Stamped by tools/linear-import/retire.py after the 2026-07-02 import
(123 issues, 11 projects). Linear is now the source of truth.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@cursor

cursor Bot commented Jul 2, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_f2da809b-e742-40c5-8eb9-25fb8fb6b4f6)

…/anyhow bumps

- RUSTSEC-2026-0194/-0195: quick-xml 0.38.4 DoS-class advisories, fix
  >=0.41, pinned transitively via object_store 0.12.5 (semver-locked by
  lancedb/surrealdb). Ignored with justification in deny.toml, the CI
  audit script, and the release-grade security-audit recipe — in lockstep.
- cargo update: quinn-proto 0.11.15 (RUSTSEC-2026-0185), anyhow 1.0.103
  (RUSTSEC-2026-0190). Lock is gitignored; CI resolves fresh.

Verified locally: audit script exit 0, cargo deny check advisories exit 0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@kpernyer

kpernyer commented Jul 2, 2026

Copy link
Copy Markdown
Contributor Author

Pushed the remaining green-main work: quick-xml RUSTSEC-2026-0194/0195 transitive ignores (deny.toml + audit script + Justfile in lockstep) and quinn-proto/anyhow advisory bumps. Audit + deny verified green locally.

Heads-up on ordering: the just ci check here will stay red until Reflective-Lab/arena-tests#3 merges — atelier's sibling-checkout pulls arena main, whose workspace references a crate that was never pushed (fixed in that PR). Merge arena-tests#3 first, then re-run checks here.

@cursor

cursor Bot commented Jul 2, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_38c913dc-6264-44c1-8413-c3ffd8316dfd)

Session scope pointed at the archived kb/Planning/MILESTONES.md and a
nonexistent bedrock-platform/EPIC.md. Floor versions (Converge >= 3.9.1,
MSRV 1.96.0, Edition 2024, unsafe forbid) were Claude-only; they bind
every agent, so they now live in AGENTS.md. CLAUDE.md keeps only
tool-specific notes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@cursor

cursor Bot commented Jul 2, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_57fbe8bd-c77d-4649-afd6-7a6c5ecbe63f)

@kpernyer
kpernyer merged commit 24e18ac into main Jul 2, 2026
9 of 11 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant