Skip to content

fix(maintenance): enforce focused checks and repair runtime boundaries - #285

Draft
lemon07r wants to merge 9 commits into
masterfrom
chore/launch-static-analysis
Draft

lemon07r wants to merge 9 commits into
masterfrom
chore/launch-static-analysis

Conversation

@lemon07r

@lemon07r lemon07r commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Windows index locks were no-ops outside one process, malformed ONNX outputs could panic, and several production test seams and unused wrappers remained. This stage implements real Windows file locks and cross-process regressions, returns typed inference errors for poisoned sessions and malformed model outputs, removes unsupported helpers, and keeps retained contracts with specific safety invariants and suppression reasons. Fresh Docker variants now select their intended Potion/ONNX backend.

First-party workspace crates inherit a small denied lint set: unsafe operations inside unsafe functions, debugging macros, unfinished implementations, undocumented unsafe blocks and unexplained suppressions. CI adds pinned Actionlint+ShellCheck, conservative Ruff, npm syntax and strict public rustdoc; ordinary Cargo gates remain locked and cover all targets. Dependency policy rejects wildcard registry requirements, unknown sources, unaudited Git revisions and native OpenSSL dependencies. Private workspace path dependencies remain supported; tag-derived versions and Rust1.88 are unchanged.

The pass fixes shell corpus-setup quoting/counting, propagates task-directory enumeration failures, isolates environment-mutating tests, fixes rustdoc errors and adds SRI to the grammar playground scripts flagged by CodeQL. CodeQL default setup is enabled and validated for Rust, Actions, Python, JavaScript and detected grammar C/C++; its earlier npm injection finding is fixed by PR283. Existing three advisory waivers remain narrowly justified.

Validation in progress: denied all-target workspace Clippy passed; full workspace tests passed on repeat after one intermittent BM25 writer-lock failure, now under investigation. Strict rustdoc and shell/Python/workflow/security checks are being completed. Windows implementation has actual Linux child-process contention/release/blocking/retry coverage; real Windows Clippy and lock tests plus actualRust1.88 CI must pass before merge. Provider-cache panic recovery and final audit dispositions follow in this PR.


Summary by cubic

Fixes Windows index locking being a no-op across processes, replaces ONNX panic paths with typed errors, removes dead helpers, and enforces a stricter lint/audit policy across CI.

Runtime fixes

  • Windows index locks now block and retry across processes, with real Linux/Windows contention coverage.
  • Poisoned ONNX sessions and malformed model outputs return typed Result errors instead of panicking.
  • Cached model loads that panic now leave the slot retryable instead of poisoning the provider cache.
  • Docker images select their intended Potion/ONNX backend via VERA_BACKEND.
  • Shell corpus-setup quoting and counting fixed; task-directory enumeration failures now propagate; environment-mutating tests run in isolated child processes.

Analysis hardening

  • Workspace lints deny debug macros, todo!/unimplemented!, unsafe operations inside unsafe functions, undocumented unsafe blocks, and unexplained suppressions.
  • CI adds pinned Actionlint/ShellCheck, conservative Ruff, npm syntax checks, all-target workspaces, and strict public rustdoc; CodeQL default setup validates Rust, Actions, Python, JavaScript, and detected C/C++.
  • cargo deny now rejects wildcard registry requirements, unknown sources, unaudited Git revisions, and native OpenSSL; playground scripts gain SRI hashes.
  • Real Windows Clippy and cross-process lock tests must pass before merge.

Written for commit 6ff70d8. Summary will update on new commits.

Review in cubic

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant