Conversation
added 7 commits
September 30, 2026 01:31
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Windows index locks were no-ops outside one process, malformed ONNX outputs could panic, and several production test seams and unused wrappers remained. This stage implements real Windows file locks and cross-process regressions, returns typed inference errors for poisoned sessions and malformed model outputs, removes unsupported helpers, and keeps retained contracts with specific safety invariants and suppression reasons. Fresh Docker variants now select their intended Potion/ONNX backend.
First-party workspace crates inherit a small denied lint set: unsafe operations inside unsafe functions, debugging macros, unfinished implementations, undocumented unsafe blocks and unexplained suppressions. CI adds pinned Actionlint+ShellCheck, conservative Ruff, npm syntax and strict public rustdoc; ordinary Cargo gates remain locked and cover all targets. Dependency policy rejects wildcard registry requirements, unknown sources, unaudited Git revisions and native OpenSSL dependencies. Private workspace path dependencies remain supported; tag-derived versions and Rust1.88 are unchanged.
The pass fixes shell corpus-setup quoting/counting, propagates task-directory enumeration failures, isolates environment-mutating tests, fixes rustdoc errors and adds SRI to the grammar playground scripts flagged by CodeQL. CodeQL default setup is enabled and validated for Rust, Actions, Python, JavaScript and detected grammar C/C++; its earlier npm injection finding is fixed by PR283. Existing three advisory waivers remain narrowly justified.
Validation in progress: denied all-target workspace Clippy passed; full workspace tests passed on repeat after one intermittent BM25 writer-lock failure, now under investigation. Strict rustdoc and shell/Python/workflow/security checks are being completed. Windows implementation has actual Linux child-process contention/release/blocking/retry coverage; real Windows Clippy and lock tests plus actualRust1.88 CI must pass before merge. Provider-cache panic recovery and final audit dispositions follow in this PR.
Summary by cubic
Fixes Windows index locking being a no-op across processes, replaces ONNX panic paths with typed errors, removes dead helpers, and enforces a stricter lint/audit policy across CI.
Runtime fixes
Resulterrors instead of panicking.VERA_BACKEND.Analysis hardening
todo!/unimplemented!, unsafe operations inside unsafe functions, undocumented unsafe blocks, and unexplained suppressions.cargo denynow rejects wildcard registry requirements, unknown sources, unaudited Git revisions, and native OpenSSL; playground scripts gain SRI hashes.Written for commit 6ff70d8. Summary will update on new commits.