Repository navigation
Conversation
Audits 30 most recent merged commits (PRs #96–#174) for CLAUDE §12 r10 compliance: user-discoverable surface change must ship human-readable docs in the same PR. Score: 22/30 N/A (no surface change), 5/8 with surface changes compliant (62.5 %). Three confirmed gaps: - Gap A (HIGH): PR #47 (ADR-0726, Vulkan drop) — docs/backends/vulkan/overview.md, docs/metrics/features.md, and docs/development/build-flags.md still describe Vulkan as an operative backend. Tracked as T-DOC-VULKAN-STALE-POST-ADR0726. - Gap B (MEDIUM): PR #87 (ADR-0749, VmafLegacyQualityRunner sunset) — no docs/development/deprecations.md entry and no migration note in docs/usage/python.md. Tracked as T-DOC-LEGACY-RUNNER-MISSING-DEPRECATION. - Gap C (LOW): PR #135 (log format standardization) — removes "Error: " prefix from CUDA error messages with no doc note. Three follow-up issues proposed (Issue A, B, C in Research-0848). No code changes in this PR; audit-only per task brief. Six deliverables (ADR-0108): (1) Research-0848: docs/research/research-0848-per-surface-doc-compliance-audit-20260529.md (2) Decision matrix in ADR-0848 §Alternatives considered (3) no rebase-sensitive invariants (4) Reproducer: git log --oneline origin/master | head -30 (auditable from commit list) (5) changelog.d/changed/per-surface-doc-compliance-audit.md (6) docs/rebase-notes.md entry added Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
enabled auto-merge (squash)
May 29, 2026 15:40
6 tasks done
lusoris
added a commit
that referenced
this pull request
May 29, 2026
…#246) ADR-0726 (Accepted 2026-05-26) declared the Vulkan backend dropped but only committed the ADR doc + changelog fragment. The actual source tree, header, build option, CI workflow jobs, and parity-gate defaults remained, causing ongoing CI failures (`vmaf: unrecognized option '--vulkan_device'`) and user confusion ("wtf I thought we dropped vulkan?"). This commit completes the removal: Source tree (77 files, ~1.4MB): - core/src/vulkan/ (runtime, queue, image-import, etc.) - core/src/feature/vulkan/ (per-feature kernels + GLSL shaders) - core/include/libvmaf/libvmaf_vulkan.h (public API header) Build system: - core/meson_options.txt: enable_vulkan option removed (replaced with an ADR-0726 stub comment) CI workflow: - .github/workflows/tests-and-quality-gates.yml: 3 jobs removed (vulkan-vif-cross-backend, vulkan-parity-matrix-gate, vulkan-vif-arc-nightly) — 318 lines Parity gate script: - scripts/ci/cross_backend_parity_gate.py: --backends default changed from ['cpu', 'vulkan'] to ['cpu', 'cuda']. Vulkan still in the BACKEND_DEVICE_FLAG / BACKEND_DEFAULT_DEVICE dicts (harmless when not in --backends list); a follow-up can prune those if desired. Out of scope for this PR (follow-ups): - core/subprojects/packagefiles/volk/ + vk-mem-alloc/ (vendored deps) - docs/backends/vulkan/ (per the PR #216 audit GAP-1 finding) - testdata/bench_all.sh FLAGS_VULKAN (bench script, not on CI hot path) - ai/scripts/collect_gpu_calibration_data.py 'vulkan' entry - 4 stale ai/ + dev/ refs to vulkan_device Unblocks: GPU-Parity Matrix Gate (was failing on missing --vulkan_device); Vulkan VIF Cross-Backend (lavapipe) — gone entirely. Verified: YAML parses, Python parses (parity gate + vif diff scripts), 0 non-Vulkan source files import the deleted internals. Co-authored-by: lusoris <lusoris@pm.me> Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
lusoris
marked this pull request as draft
May 30, 2026 01:18
auto-merge was automatically disabled
May 30, 2026 01:18
Pull request was converted to draft
lusoris
marked this pull request as ready for review
May 31, 2026 13:32
Contributor
Author
|
Superseded by master after 143-PR merge marathon 2026-05-31; diff-extract empty. |
Contributor
Author
|
Superseded by #527 — bundled per 2026-06-01 triage. |
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
…291 state.md drift sweep + #233 changelog concat fix) (#527) * docs(lint): NOLINT cluster audit and refactor plan (ADR-0780) Swept all 218 NOLINT annotations in core/src/ for clusters of five or more identical suppressions per file. Identified five clusters (71 annotations): - 21 bare performance-no-int-to-ptr in GPU slab allocators — ADR-0278 non-compliant (no citations); scheduled for SLAB_FIELD macro (PR B). - 12 bugprone-implicit-widening in SYCL stride arithmetic — scheduled for explicit (ptrdiff_t) casts that eliminate the suppression entirely (PR A). - 14 misc-const-correctness in SYCL atomic_ref loops — fold into existing NOLINTBEGIN/NOLINTEND block (PR C). - 13 bare readability-function-size in integer_adm.c — ADR-0278 non-compliant; scheduled for NOLINTBEGIN block consolidation (PR C). - 11 readability-function-size on SYCL kernel entry-points — load-bearing per ADR-0141; no change planned. Deliverables: research digest, ADR-0780 (Proposed), changelog fragment. Follow-up refactor PRs A–C are independent. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * docs(process): per-surface doc compliance audit — last 30 PRs (ADR-0848) Audits 30 most recent merged commits (PRs #96–#174) for CLAUDE §12 r10 compliance: user-discoverable surface change must ship human-readable docs in the same PR. Score: 22/30 N/A (no surface change), 5/8 with surface changes compliant (62.5 %). Three confirmed gaps: - Gap A (HIGH): PR #47 (ADR-0726, Vulkan drop) — docs/backends/vulkan/overview.md, docs/metrics/features.md, and docs/development/build-flags.md still describe Vulkan as an operative backend. Tracked as T-DOC-VULKAN-STALE-POST-ADR0726. - Gap B (MEDIUM): PR #87 (ADR-0749, VmafLegacyQualityRunner sunset) — no docs/development/deprecations.md entry and no migration note in docs/usage/python.md. Tracked as T-DOC-LEGACY-RUNNER-MISSING-DEPRECATION. - Gap C (LOW): PR #135 (log format standardization) — removes "Error: " prefix from CUDA error messages with no doc note. Three follow-up issues proposed (Issue A, B, C in Research-0848). No code changes in this PR; audit-only per task brief. Six deliverables (ADR-0108): (1) Research-0848: docs/research/research-0848-per-surface-doc-compliance-audit-20260529.md (2) Decision matrix in ADR-0848 §Alternatives considered (3) no rebase-sensitive invariants (4) Reproducer: git log --oneline origin/master | head -30 (auditable from commit list) (5) changelog.d/changed/per-surface-doc-compliance-audit.md (6) docs/rebase-notes.md entry added Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * docs(state): close T-LEGACY-RUNNER-ANSNR-BROKEN + T-LEGACY-RUNNER-STUB-MISSING Both rows referenced classes / imports that no longer exist on master: 1. T-LEGACY-RUNNER-ANSNR-BROKEN — AnsnrFeatureExtractor was deleted by PR #283 (merged at faede7a). The class is absent from compat/python-vmaf/core/feature_extractor.py on master tip d45d503. The Netflix golden assertions still cover the integer-path VMAF score (Rule #1 preserved). 2. T-LEGACY-RUNNER-STUB-MISSING-2026-05-29 — VmafLegacyQualityRunner import-time failure: the class was removed in ADR-0749 / PR #87 and python/test/quality_runner_test.py was updated by the ADR-0749 sunset PR to drop the import (only a removed-comment placeholder at line 49 remains). Moved both rows from Open to Recently closed with verified-on-master reproducer commands. No code changes — documentation cleanup only. Deliverables (ADR-0108): - [x] **Research digest**: no digest needed: state.md hygiene - [x] **Decision matrix**: no alternatives: only-one-way fix - [x] **AGENTS.md invariant**: no rebase-sensitive invariants - [x] **Reproducer**: `git show origin/master:compat/python-vmaf/core/feature_extractor.py | grep -c 'class AnsnrFeatureExtractor'` returns 0; `git show origin/master:python/test/quality_runner_test.py | grep -c '^from.*VmafLegacy'` returns 0. - [x] **Changelog**: changelog.d/changed/state-md-drift-sweep-20260530.md - [x] **Rebase notes**: no rebase impact: docs only Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * docs(state): migrate 3 Vulkan rows to Recently closed (ADR-0726 supersession) ADR-0726 (Vulkan backend dropped 2026-05-28, PR #47) structurally closes three long-standing Vulkan Open rows by removing the affected code path entirely: - T-VK-1.4-BUMP — NVIDIA driver 595.71+ FP-contraction regression - T-VK-CIEDE-F32-F64 — NVIDIA Vulkan f32/f64 ciede precision gap - T-VK-VIF-1.4-RESIDUAL-ARC — Intel Arc A380 vif residual on Mesa-ANV The entire `core/src/vulkan/`, `core/src/feature/vulkan/`, and `core/include/libvmaf/libvmaf_vulkan.h` surface no longer exists on master, so each row now has a verified empty-path reproducer. Native CUDA / HIP / SYCL backends cover every vendor formerly served by Vulkan (see ADR-0726 §Context). Combined with the legacy-runner closures already in this PR (T-LEGACY-RUNNER-ANSNR-BROKEN + T-LEGACY-RUNNER-STUB-MISSING-2026-05-29), this brings the Open section from 14 → 11 rows. Row counts (verified): Open 11 + Deferred 4 + Recently closed 137 + Confirmed not-affected 1 = 153 total T- rows in tree. * chore(changelog): fix concat awk boundary + consolidate perf/ fragments (ADR-0221) Fix `concat-changelog-fragments.sh` --check/--write awk block-boundary: the previous `/^## [^[]/` pattern terminated the Unreleased block on any `## Heading` embedded inside a fragment (e.g. `## Added`, `## [perf] …`). Switch to `/^## \[(Unreleased|[0-9])/` which matches only versioned-release headers and the `[Unreleased]` sentinel, making `--check` deterministic. Tightened the `--write` awk pass with the same fix. Consolidate 32 fragments from non-standard `changelog.d/perf/` (27) and `changelog.d/performance/` (5) into the recognised `changed/` section with `perf-` filename prefix per ADR-0221 KaC convention. Remove 3 duplicate stubs: `ort-run-stack-arrays-f3b.md`, `adm-pnorm-deferred-comment.md`, `fixed/vmaf-tune-predictor-directory-corpus.md` (richer versions retained). Rename `changed/fr-regressor-v3-namespace.md` → `…-adr-appendix.md` to resolve filename collision with `added/fr-regressor-v3-namespace.md`. Regenerate CHANGELOG.md Unreleased block via `--write`; `--check` exits 0. no rebase impact: changelog.d/ + scripts/release/ only, no upstream C touched. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(bundle): add changelog fragment for docs/hygiene bundle PR Adds changelog.d/changed/bundle-docs-hygiene.md summarising the four source PRs: #127 (NOLINT audit), #216 (doc compliance audit), #291 (state.md drift sweep), #233 (changelog concat fix). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Lusoris <lusoris@pm.me>
6 of 11 tasks
lusoris
added a commit
that referenced
this pull request
Jun 6, 2026
Two Open rows in docs/state.md referred to bugs already in the Recently Closed section: - T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 was closed by PR #680; the Open row citing "PR #214 (OPEN)" is removed. - T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 had a stale duplicate referencing "PR #215 (OPEN)"; the duplicate is removed. The correct owner-driven copy (PR #215 closed without merging, fresh PR required) is retained. T-DOC-LEGACY-RUNNER-MISSING-DEPRECATION-2026-05-29 updated: PR #216 was closed without merging 2026-05-30; the row now reflects that docs/development/deprecations.md exists (PR #605) but still lacks the VmafLegacyQualityRunner entry. Owner-driven. Also fixes a pre-existing data corruption: T-GPU-COVERAGE-STABLE-WEEKS appeared twice on one line in Recently Closed (no newline separator); corrected to a single properly-formatted row. Net Open change: -2 rows. no digest needed: trivial doc sweep no alternatives: only-one-way fix no rebase-sensitive invariants: docs/state.md only Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 6, 2026
…#724) Two Open rows in docs/state.md referred to bugs already in the Recently Closed section: - T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 was closed by PR #680; the Open row citing "PR #214 (OPEN)" is removed. - T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 had a stale duplicate referencing "PR #215 (OPEN)"; the duplicate is removed. The correct owner-driven copy (PR #215 closed without merging, fresh PR required) is retained. T-DOC-LEGACY-RUNNER-MISSING-DEPRECATION-2026-05-29 updated: PR #216 was closed without merging 2026-05-30; the row now reflects that docs/development/deprecations.md exists (PR #605) but still lacks the VmafLegacyQualityRunner entry. Owner-driven. Also fixes a pre-existing data corruption: T-GPU-COVERAGE-STABLE-WEEKS appeared twice on one line in Recently Closed (no newline separator); corrected to a single properly-formatted row. Net Open change: -2 rows. no digest needed: trivial doc sweep no alternatives: only-one-way fix no rebase-sensitive invariants: docs/state.md only Co-authored-by: Lusoris <lusoris@pm.me> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 12, 2026
…CI) (#868) * fix(codeql): resolve HIGH-severity security-cpp-high alerts (23 sites) - cpp/integer-multiplication-cast-to-long (11): pre-cast one operand to size_t / double / ptrdiff_t before int*int multiplications in cambi.c, float_vif.c (log message), iqa/convolve.c (img_offset), moment.c, psnr.c, and vif_tools.c (four memcpy size expressions). Add stddef.h to convolve.c for ptrdiff_t. - cpp/incomplete-parity-check (3): change `% 2 == 1` to `% 2 != 0` in vif_tools.c (assert), svm.cpp (powi loop), pdjson.c (JSON object key/value alternation). The == 1 form is wrong for negative operands; != 0 is always correct. - cpp/wrong-type-format-argument (2): fix float_vif.c error log that printed size_t fields scaled_w/scaled_h with %d; change to %zu. - cpp/world-writable-file-creation (1): in vmaf.cpp replace bare fopen("wb") with open(O_WRONLY|O_CREAT|O_TRUNC, 0644)+fdopen() on POSIX so the created file is never world-writable independent of the caller's umask. Add <fcntl.h>. - cpp/path-injection (4): in test_output.c resolve the mkstemp-created path through realpath() immediately after creation, breaking the taint chain from getenv("TMPDIR") to the vmaf_write_output call site. - cpp/toctou-race-condition (2): skipped — both sites are in test cleanup (RMDIR after stat assertion). The stat result drives a test assertion, not a security-sensitive access decision; no atomic replacement of open() is applicable to rmdir. Reported as skipped. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(codeql): resolve security-python-and-ci CodeQL alerts Fixes 18 open CodeQL alerts across the Python and CI categories: - yaml.github-actions.security.run-shell-injection (#661): move github.event_name, github.base_ref, and github.event.before from inline ${{...}} interpolation to env: vars in the SYCL clang-tidy detect step of lint-and-format.yml. - python.lang.security.use-defused-xml-parse (#216, #217): replace xml.etree.ElementTree with defusedxml.ElementTree in feature_extractor.py and quality_runner.py; add defusedxml>=0.7.1 to python/pyproject.toml and python/requirements.txt. - py/undefined-export (#352, #353, #354, #616): restructure aiutils/__init__.py to do a conditional eager import of the parquet helpers so the names are defined when pyarrow is present, and only include them in __all__ when the import succeeded. - py/stack-trace-exposure (#178, #179, #585): log exception detail server-side and return a generic message to the HTTP client in http_transport.py _handle_score (invalid JSON, bad params, scorer error branches). - python.lang.security.audit.dangerous-subprocess-use-tainted-env-args (#227, #372): add shlex.quote() around user-supplied path arguments passed into shell strings in extract_ugc_features.py and test_bbb_e2e_v5_bug_cluster.py. - py/file-not-closed (#677, #678): replace bare open() calls with context managers in test_coverage_round3.py. - py/redundant-comparison (#427, #431): remove redundant assert not (x != y) lines that duplicate the preceding assert x == y. - py/equals-hash-mismatch (#182): convert RdPoint to frozen=True dataclass so __eq__ and __hash__ are generated consistently. - py/inheritance/signature-mismatch (#197): add result_dict=None default to EnsembleVmafQualityRunner._populate_result_dict so the signature is compatible with the base class. - py/multiple-definition (#201): drop redundant assignment to feature_found in feature_extractor.py wildcard discovery path. - py/str-format/surplus-named-argument (#204): remove unused dataset= kwarg from the format() call in routine.py. Skipped: python.lang.security.audit.insecure-file-permissions (#373) — the Unix socket at 0o660 is intentional (Go sidecar node must write to it and runs as the same UNIX group); tightening to 0o644 would break the IPC channel. Skipped: py/path-injection (#180, #181) — _validate_path() already resolves the path and checks it against an allowlist before any file operation; the data flow is secure and the CodeQL dataflow trace is a false positive on this allowlisted pattern. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Lusoris <lusoris@pm.me> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Findings
docs/backends/vulkan/overview.md,docs/metrics/features.md,docs/development/build-flags.mdstill describe Vulkan as activedocs/development/deprecations.mdentry; no migration note"Error: "prefix from CUDA error messages; no doc note5 / 8 PRs with surface changes compliant (62.5%)
Follow-up Issues Proposed
docs/backends/vulkan/+docs/metrics/features.md+docs/development/build-flags.mdfor Vulkan removaldocs/development/deprecations.mddocs/backends/cuda/overview.mdTest plan
docs/adr/0848-per-surface-doc-compliance-audit.mdpresentdocs/research/research-0848-per-surface-doc-compliance-audit-20260529.mdpresentdocs/state.mdhas T-DOC-VULKAN-STALE-POST-ADR0726 and T-DOC-LEGACY-RUNNER-MISSING-DEPRECATION rowsSix deliverables (ADR-0108)
docs/research/research-0848-per-surface-doc-compliance-audit-20260529.mdgit log --oneline origin/master | head -30changelog.d/changed/per-surface-doc-compliance-audit.mddocs/rebase-notes.mdentry added🤖 Generated with Claude Code