Repository navigation
fix(governance): normalize licensing and project state - #116
Merged
Merged
Conversation
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Contributor
|
Important Review skippedToo many files! This PR contains 128 files, which is 28 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configuration
📒 Files selected for processing (128)
You can disable this status message by setting the
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath
marked this pull request as ready for review
October 3, 2026 21:10
hyperpolymath
added a commit
that referenced
this pull request
Oct 4, 2026
…nic family (#117) Closes #49. ## What #49 asked, and where it stands Re-audited all three items against the current tree (the gate has evolved since the issue was filed in June — it now scopes checks 2–3 to production code and accepts `// SAFETY:`-justified FFI, both correct refinements): | Issue item | Disposition | |---|---| | 5 missing SPDX headers | **Done** (landed earlier, e.g. #116). Verified: 0 missing. | | 20 `unsafe` in `src/` | **10 remain, all justified**: each carries a contiguous `// SAFETY:` comment; `attest` and `recompute-wasm` (the only crates with `unsafe`) both set `#![deny(clippy::undocumented_unsafe_blocks)]`. These are `#[no_mangle] extern "C"` FFI trust boundaries, which *cannot* be written without `unsafe` — elimination is impossible, documentation is the correct posture, and the gate enforces it. | | 61 `unwrap`/`expect` in `src/` | **All remaining hits are test-only**: every one sits inside a `#[cfg(test)]` module or under `src/*/tests/` (plus `testing.expect` in Zig test files, out of the Rust gate's scope by design). Production count is 0. | The gate already passed 6/6 — but the audit found one genuine hole in the same SPARK-grade family that the gate didn't cover: a production `panic!`. ## Changes * `src/interface/lsp/src/main.rs` — the request dispatcher `panic!`'d (crashing the whole server) when a request's method matched but its params failed JSON deserialization. It now answers JSON-RPC `Invalid params` (-32602) naming the method and the error, via a new three-outcome `Cast` type that rescues the request id before `extract()` consumes it. Also adds `#![deny(clippy::unwrap_used, clippy::expect_used)]`, mirroring `vclt-gate`, and dedupes error responses through a new `send_error` helper. * `tests/aspect_tests.sh` — check 3 now also rejects `panic!`/`unreachable!`/`todo!`/`unimplemented!` in production `src/`, matching the documented `vcltotal-parse` SPARK-grade lint set (the estate pattern per `parse/src/lib.rs`). * `src/interface/parse/src/parser.rs` — one doc comment reworded (`panic!` → `panic`, meaning unchanged) so the textual gate stays precise. * `CHANGELOG.adoc` — `[Unreleased] / Fixed` entries. ## Validation * `bash tests/aspect_tests.sh` → **6 passed, 0 failed** (before and after; the gate is now strictly stronger). * Negative test: temporarily injecting `panic!("boom")` into production `src/` makes the new check FAIL as intended; removed afterwards. * `bash -n` on the script and `git diff --check` clean. * Note: `vcltotal-lsp` is not built by standalone CI (it needs the echidna sibling path-dep; only the estate e2e layout compiles it), and this sandbox has no Rust toolchain — so the `main.rs` change was verified by inspection against the [lsp-server 0.7 API on docs.rs](https://docs.rs/lsp-server/0.7.7/lsp_server/struct.Request.html) (`Request { pub id, pub method, pub params }`, `Request: Clone`, `extract` signature, `ExtractError::{MethodMismatch, JsonError { method, error }}` shapes all confirmed). Only previously-unused-but-public API surface (`req.id.clone()`) is introduced; every other construct mirrors adjacent existing code. ## Suggested follow-up (not in this PR) Per-crate `#![deny(clippy::unwrap_used, clippy::expect_used, clippy::panic, …)]` on the remaining lib crates (`lsp`, `dap`, `fmt`, `lint`, `attest`, `echidna-client`) with `allow`s in their test modules, mirroring `vcltotal-parse`. Deliberately left out: it needs `cargo clippy` validation per crate, which isn't available in this sandbox — and #49 itself warns against blind passes. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements the repository-side work tracked by #53. This is a draft pending explicit owner confirmation of the license policy and branch-protection change.
mainlicense as MPL-2.0. Removed the unused AGPL license text; no source file currently declares AGPL. Corrected invalid PMPL SPDX headers, package/release metadata, and misleading legacy license wording. The ethical-use exhibits now expressly state they are non-binding guidance and do not modify MPL-2.0.just license-check, pre-commit, the K9/Must contract, and the CI checklicense-policy..machine_readable/STATE.a2mlto reflect the actual VCL-UT implementation, proof corpus, limitations, and next actions; removes the byte-identical6a2/STATE.a2mlmirror. Documents the distinct roles of the four contractile locations and removes the remaining template-state wording from the AI entry point.Validation
reuse lint— pass (0 missing, invalid, deprecated, or unused licenses).scripts/check-license-policy.sh— pass; negative test confirmed the documentation path rule rejects MPL-2.0..githooks/validate-a2ml.sh— pass (121 files, 0 errors/warnings).pre-commit validate-config, shell syntax, TOML/JSON/YAML parsing, andgit diff --check— pass.https://github.com/hyperpolymath/a2ml-pre-commitremote returning “Repository not found”. Strict K9 validation also flags the existingcontainer/deploy.k9.nclenvelope-format mismatch. Cargo, Idris2, and Nickel are not installed in this sandbox, so build/proof corpus execution was not possible here.Owner actions before this can be merged/closed
license-policystatus check required in branch protection/rulesets. GitHub reports its exact check context aslicense-policy; this session's integration cannot read or change branch-protection settings (HTTP 403).This PR intentionally does not auto-close #53; owner confirmation and the required-check setting are still needed for full conclusion.
GitHub CI status (observed 2026-10-03)
The PR-head
license-policyjob passes in REUSE compliance run 37153345024; the A2ML validation job also passes here (the corresponding job failed onmainbefore this PR). Parse Gate, E2E/property tests, CodeQL, OpenSSF, and the dedicated Hypatia scan passed.Several other red checks are pre-existing on
mainand reproduce on this PR: K9 contract validation (PR, main) rejectscontainer/deploy.k9.nclbecause its metadata envelope differs from the validator's expected literalK9!/top-level pedigree format; the Governance workflow linter (PR, main) fails at “Check SPDX headers + permissions”; Static Analysis Gate / Hypatia critical findings (PR, main); Rust CI / Clippy (PR, main); and Cargo Audit (PR, main). These are not attributed to this change; the Actions log archive endpoint returned EOF when detailed failed-step logs were requested. The K9 validator mismatch is documented rather than suppressed or “fixed” by weakening the gate.At the time checked, Proof Corpus remained in progress and the large Backend Matrix remained queued, so this is not a claim that the full CI suite completed. Maintainers should resolve or explicitly disposition the pre-existing red checks as appropriate for branch protection, then wait for the proof/matrix jobs.
Additional maintainer follow-up
component_pedigree/metadata.magic_number/trust_levelrepresentation with regression coverage, or migrate the deployment config to the canonical format). Also triage the baseline governance, Hypatia, Clippy, and Cargo Audit failures if they are required checks.