[ci] Audit live CI inputs against policy - #3578
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## Gt4itljw3xh6tci2mjqj4z245i6pwle2i #3578 +/- ##
==================================================================
Coverage 91.85% 91.85%
==================================================================
Files 20 20
Lines 6093 6093
==================================================================
Hits 5597 5597
Misses 496 496 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5070ce31b1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
5070ce3 to
fac6e43
Compare
|
Authored by an agent, posting via joshlf's account @codex review |
|
Codex Review: Didn't find any major issues. Another round soon, please! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
4864e15 to
b49d72d
Compare
fac6e43 to
77f85fe
Compare
12e15aa to
1efd245
Compare
|
Authored by an agent, posting via joshlf's account @codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1efd245312
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
5488531 to
da7ad19
Compare
1efd245 to
205aa5e
Compare
|
Authored by an agent, posting via joshlf's account @codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 205aa5e0fe
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
da7ad19 to
d6bc5ea
Compare
205aa5e to
467e8ab
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 467e8abfae
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
467e8ab to
ce33423
Compare
d6bc5ea to
82ce4ba
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ce33423ce2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
6cc20d1 to
b3a0666
Compare
82ce4ba to
c84c440
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b3a0666196
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
c84c440 to
fec9a20
Compare
b3a0666 to
0128ac8
Compare
fec9a20 to
0adf985
Compare
0128ac8 to
1e67168
Compare
Collect repository packages, resolved dependencies, features, and Cargo targets with locked, offline Cargo metadata, then validate every policy reference against the live checkout before planning work. Disable rustup's automatic toolchain installation separately because Cargo cannot apply `--offline` until after the rustup proxy has selected a toolchain. Pin Cargo's target directory so an ambient override cannot move the generated-output exemption onto package source. Retain Cargo's complete PackageId dependency graph instead of collapsing packages by name. Validate semantic toolchains against every reachable resolved package, including external transitive dependencies, while retaining conservative declared workspace edges. Name external packages as name@version in diagnostics so duplicate package names stay distinct. Derive the stable feature closure and its nightly-only complement from Cargo's complete feature graph. Follow plain and strong optional- dependency edges according to Cargo semantics while leaving `dep:` and weak edges non-activating. Reject an all-features profile on a non-nightly toolchain whenever the selected package has a nonempty nightly complement. Future feature changes therefore fail the audit instead of silently moving nightly-only coverage onto stable. Require an explicit no-default profile if a future manifest introduces default features. Accept Rust's two-component and dotted target names without assuming every target is a three-part triple. Validate each Cargo target's exact kind and crate-type pairing so representation drift cannot silently change which artifact CI exercises. Tie each policy execution mode to the current x86_64 Linux image, including the explicit native i686 userspace and the one thumb-specific command exception. Record the package edition and every target's effective edition. Derive each package's compiler floor from both its exact `rust-version` and the reviewed edition floors, then check every semantic toolchain against the full resolved dependency closure. A target-level edition override or a newly reachable dependency therefore cannot silently make a planned cell impossible to run. Read the checked-in Cargo.lock format before invoking Cargo. Require an explicit, reviewed reader floor for V3 and V4, and reject the ambiguous unmarked V1/V2 formats and unknown future formats. Check the Cargo release paired with every semantic Rust toolchain against that floor. Dated nightlies remain deliberately incomparable with stable release numbers. Store exact target-support evidence in `ci/rust-target-support.toml` for every selected compiler version. Require equality with the union of ordinary, Miri, and semver targets, rather than accepting a stale superset. Policy, target-set, or toolchain changes therefore fail until the evidence is updated. An ignored test can query rustup for every exact compiler and verify the complete catalog when maintainers intentionally change target coverage. Teach the stable and nightly pin roller to capture the old typed pin and run a typed refresh command after changing the manifest. The command reconstructs and validates the pre-roll state, rejects unrelated drift, queries the exact new toolchain, handles an old version retained by another source and a new version already shared by another source, then renders a canonical sorted catalog. Other policy changes use canonical manual edits followed by the same all-toolchain verifier; checked-in comments identify this coordination explicitly. Replace the catalog through retained policy, manifest, and catalog handles. Recheck all three identities immediately before an atomic rename, preserve permissions, sync the replacement and parent directory, and clean up unique temporary files on failure. Let Cargo and rustc remain authoritative for custom targets and build-std configuration; the ordinary wrapper does not impose a second incomplete target model. Preflight the supported `.cargo/config.toml` shape before invoking Cargo. Reject unreviewed top-level mechanisms and the legacy `.cargo/config` name, which Cargo gives precedence even when `config.toml` is present. Require the exact reviewed environment map, follow every declared source-replacement chain, and reject missing, ambiguous, or cyclic endpoints. Require each terminal directory source to use a local relative spelling and resolve to a directory inside the checkout. Canonicalize trusted manifests, Cargo targets, configured directory sources, and baseline paths before using them. Reject symbolic links which leave the checkout, require every resolved manifest and target to remain inside it, and distinguish missing baseline inputs from other file-system errors. Recursively inspect each resolved package tree so a nested module or macro-input symlink absent from Cargo metadata cannot escape the checkout. Also validate the narrower line-oriented Cargo.toml grammar consumed by build.rs. Fail when packages, target kinds, crate types, examples, required features, baseline paths, or toolchain sources escape classification. Keep all collected data deterministic and report independent inventory errors together. Cargo metadata remains authoritative; this layer checks coordination without copying its package or feature lists into policy. Tests: focused feature, target, graph, version, edition, lockfile, configuration, path-containment, target-refresh, live-audit, and mutation tests. *Authored by an agent, posting via joshlf's account* gherrit-pr-id: Gocqawbn3p3zj7xyfo7etk6vo4633r3tn
1e67168 to
c87afd9
Compare
|
Authored by an agent, posting via joshlf's account @codex review Please review the current head, |
|
Codex Review: Didn't find any major issues. Hooray! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Collect repository packages, resolved dependencies, features, and Cargo
targets with locked, offline Cargo metadata, then validate every policy
reference against the live checkout before planning work. Disable
rustup's automatic toolchain installation separately because Cargo
cannot apply
--offlineuntil after the rustup proxy has selected atoolchain. Pin Cargo's target directory so an ambient override cannot
move the generated-output exemption onto package source.
Retain Cargo's complete PackageId dependency graph instead of
collapsing packages by name. Validate semantic toolchains against every
reachable resolved package, including external transitive dependencies,
while retaining conservative declared workspace edges. Name external
packages as name@version in diagnostics so duplicate package names stay
distinct.
Derive the stable feature closure and its nightly-only complement from
Cargo's complete feature graph. Follow plain and strong optional-
dependency edges according to Cargo semantics while leaving
dep:andweak edges non-activating. Reject an all-features profile on a
non-nightly toolchain whenever the selected package has a nonempty
nightly complement. Future feature changes therefore fail the audit
instead of silently moving nightly-only coverage onto stable.
Require an explicit no-default profile if a future manifest introduces
default features. Accept Rust's two-component and dotted target names
without assuming every target is a three-part triple. Validate each
Cargo target's exact kind and crate-type pairing so representation drift
cannot silently change which artifact CI exercises. Tie each policy
execution mode to the current x86_64 Linux image, including the explicit
native i686 userspace and the one thumb-specific command exception.
Record the package edition and every target's effective edition. Derive
each package's compiler floor from both its exact
rust-versionand thereviewed edition floors, then check every semantic toolchain against the
full resolved dependency closure. A target-level edition override or a
newly reachable dependency therefore cannot silently make a planned
cell impossible to run.
Read the checked-in Cargo.lock format before invoking Cargo. Require an
explicit, reviewed reader floor for V3 and V4, and reject the ambiguous
unmarked V1/V2 formats and unknown future formats. Check the Cargo
release paired with every semantic Rust toolchain against that floor.
Dated nightlies remain deliberately incomparable with stable release
numbers.
Store exact target-support evidence in
ci/rust-target-support.tomlforevery selected compiler version. Require equality with the union of
ordinary, Miri, and semver targets, rather than accepting a stale
superset. Policy, target-set, or toolchain changes therefore fail until
the evidence is updated. An ignored test can query rustup for every
exact compiler and verify the complete catalog when maintainers
intentionally change target coverage.
Teach the stable and nightly pin roller to capture the old typed pin and
run a typed refresh command after changing the manifest. The command
reconstructs and validates the pre-roll state, rejects unrelated drift,
queries the exact new toolchain, handles an old version retained by
another source and a new version already shared by another source, then
renders a canonical sorted catalog. Other policy changes use canonical
manual edits followed by the same all-toolchain verifier; checked-in
comments identify this coordination explicitly.
Replace the catalog through retained policy, manifest, and catalog
handles. Recheck all three identities immediately before an atomic
rename, preserve permissions, sync the replacement and parent
directory, and clean up unique temporary files on failure. Let Cargo
and rustc remain authoritative for custom targets and build-std
configuration; the ordinary wrapper does not impose a second incomplete
target model.
Preflight the supported
.cargo/config.tomlshape before invokingCargo. Reject unreviewed top-level mechanisms and the legacy
.cargo/configname, which Cargo gives precedence even whenconfig.tomlis present. Require the exact reviewed environment map,follow every declared source-replacement chain, and reject missing,
ambiguous, or cyclic endpoints. Require each terminal directory source
to use a local relative spelling and resolve to a directory inside the
checkout.
Canonicalize trusted manifests, Cargo targets, configured directory
sources, and baseline paths before using them. Reject symbolic links
which leave the checkout, require every resolved manifest and target to
remain inside it, and distinguish missing baseline inputs from other
file-system errors. Recursively inspect each resolved package tree so a
nested module or macro-input symlink absent from Cargo metadata cannot
escape the checkout.
Also validate the narrower line-oriented Cargo.toml grammar consumed by
build.rs. Fail when packages, target kinds, crate types, examples,
required features, baseline paths, or toolchain sources escape
classification. Keep all collected data deterministic and report
independent inventory errors together. Cargo metadata remains
authoritative; this layer checks coordination without copying its
package or feature lists into policy.
Tests: focused feature, target, graph, version, edition, lockfile,
configuration, path-containment, target-refresh, live-audit, and
mutation tests.
Authored by an agent, posting via joshlf's account
Latest Update: v29 — Compare vs v28
📚 Full Patch History
Links show the diff between the row version and the column version.
⬇️ Download this PR
Branch
git fetch origin refs/heads/Gocqawbn3p3zj7xyfo7etk6vo4633r3tn && git checkout -b pr-Gocqawbn3p3zj7xyfo7etk6vo4633r3tn FETCH_HEADCheckout
git fetch origin refs/heads/Gocqawbn3p3zj7xyfo7etk6vo4633r3tn && git checkout FETCH_HEADCherry Pick
git fetch origin refs/heads/Gocqawbn3p3zj7xyfo7etk6vo4633r3tn && git cherry-pick FETCH_HEADPull
Stacked PRs enabled by GHerrit.