Skip to content

docs(process): per-surface doc compliance audit — last 30 PRs (ADR-0848) - #216

Closed
lusoris wants to merge 1 commit into
masterfrom
docs/per-surface-audit-session-20260529
Closed

lusoris wants to merge 1 commit into
masterfrom
docs/per-surface-audit-session-20260529

Conversation

@lusoris

@lusoris lusoris commented May 29, 2026

Copy link
Copy Markdown
Contributor

Summary

Findings

Gap PR Severity Missing
Vulkan removal docs stale #47 (ADR-0726) HIGH docs/backends/vulkan/overview.md, docs/metrics/features.md, docs/development/build-flags.md still describe Vulkan as active
LegacyQualityRunner deprecation #87 (ADR-0749) MEDIUM No docs/development/deprecations.md entry; no migration note
CUDA log format change #135 LOW Removes "Error: " prefix from CUDA error messages; no doc note

5 / 8 PRs with surface changes compliant (62.5%)

Follow-up Issues Proposed

  • Issue A: Clean up docs/backends/vulkan/ + docs/metrics/features.md + docs/development/build-flags.md for Vulkan removal
  • Issue B: Add VmafLegacyQualityRunner to docs/development/deprecations.md
  • Issue C: Note CUDA log format change in docs/backends/cuda/overview.md

Test plan

  • Pre-commit hooks pass (green above)
  • docs/adr/0848-per-surface-doc-compliance-audit.md present
  • docs/research/research-0848-per-surface-doc-compliance-audit-20260529.md present
  • docs/state.md has T-DOC-VULKAN-STALE-POST-ADR0726 and T-DOC-LEGACY-RUNNER-MISSING-DEPRECATION rows
  • ADR README has 0848 row

Six deliverables (ADR-0108)

  • (1) Research digest: docs/research/research-0848-per-surface-doc-compliance-audit-20260529.md
  • (2) Decision matrix in ADR-0848 §Alternatives considered
  • (3) no rebase-sensitive invariants
  • (4) Reproducer: git log --oneline origin/master | head -30
  • (5) changelog.d/changed/per-surface-doc-compliance-audit.md
  • (6) docs/rebase-notes.md entry added

🤖 Generated with Claude Code

Audits 30 most recent merged commits (PRs #96–#174) for CLAUDE §12 r10
compliance: user-discoverable surface change must ship human-readable docs
in the same PR.

Score: 22/30 N/A (no surface change), 5/8 with surface changes compliant
(62.5 %). Three confirmed gaps:

- Gap A (HIGH): PR #47 (ADR-0726, Vulkan drop) — docs/backends/vulkan/overview.md,
  docs/metrics/features.md, and docs/development/build-flags.md still describe
  Vulkan as an operative backend. Tracked as T-DOC-VULKAN-STALE-POST-ADR0726.
- Gap B (MEDIUM): PR #87 (ADR-0749, VmafLegacyQualityRunner sunset) — no
  docs/development/deprecations.md entry and no migration note in
  docs/usage/python.md. Tracked as T-DOC-LEGACY-RUNNER-MISSING-DEPRECATION.
- Gap C (LOW): PR #135 (log format standardization) — removes "Error: " prefix
  from CUDA error messages with no doc note.

Three follow-up issues proposed (Issue A, B, C in Research-0848). No code
changes in this PR; audit-only per task brief.

Six deliverables (ADR-0108):
(1) Research-0848: docs/research/research-0848-per-surface-doc-compliance-audit-20260529.md
(2) Decision matrix in ADR-0848 §Alternatives considered
(3) no rebase-sensitive invariants
(4) Reproducer: git log --oneline origin/master | head -30 (auditable from commit list)
(5) changelog.d/changed/per-surface-doc-compliance-audit.md
(6) docs/rebase-notes.md entry added

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris
lusoris enabled auto-merge (squash) May 29, 2026 15:40
lusoris added a commit that referenced this pull request May 29, 2026
…#246)

ADR-0726 (Accepted 2026-05-26) declared the Vulkan backend dropped but only
committed the ADR doc + changelog fragment. The actual source tree, header,
build option, CI workflow jobs, and parity-gate defaults remained, causing
ongoing CI failures (`vmaf: unrecognized option '--vulkan_device'`) and user
confusion ("wtf I thought we dropped vulkan?").

This commit completes the removal:

Source tree (77 files, ~1.4MB):
  - core/src/vulkan/                  (runtime, queue, image-import, etc.)
  - core/src/feature/vulkan/          (per-feature kernels + GLSL shaders)
  - core/include/libvmaf/libvmaf_vulkan.h (public API header)

Build system:
  - core/meson_options.txt: enable_vulkan option removed (replaced with
    an ADR-0726 stub comment)

CI workflow:
  - .github/workflows/tests-and-quality-gates.yml: 3 jobs removed
    (vulkan-vif-cross-backend, vulkan-parity-matrix-gate,
    vulkan-vif-arc-nightly) — 318 lines

Parity gate script:
  - scripts/ci/cross_backend_parity_gate.py: --backends default changed
    from ['cpu', 'vulkan'] to ['cpu', 'cuda']. Vulkan still in the
    BACKEND_DEVICE_FLAG / BACKEND_DEFAULT_DEVICE dicts (harmless when
    not in --backends list); a follow-up can prune those if desired.

Out of scope for this PR (follow-ups):
  - core/subprojects/packagefiles/volk/ + vk-mem-alloc/ (vendored deps)
  - docs/backends/vulkan/ (per the PR #216 audit GAP-1 finding)
  - testdata/bench_all.sh FLAGS_VULKAN (bench script, not on CI hot path)
  - ai/scripts/collect_gpu_calibration_data.py 'vulkan' entry
  - 4 stale ai/ + dev/ refs to vulkan_device

Unblocks: GPU-Parity Matrix Gate (was failing on missing --vulkan_device);
Vulkan VIF Cross-Backend (lavapipe) — gone entirely.

Verified: YAML parses, Python parses (parity gate + vif diff scripts),
0 non-Vulkan source files import the deleted internals.

Co-authored-by: lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
@lusoris
lusoris marked this pull request as draft May 30, 2026 01:18
auto-merge was automatically disabled May 30, 2026 01:18

Pull request was converted to draft

@lusoris
lusoris marked this pull request as ready for review May 31, 2026 13:32
@lusoris

lusoris commented May 31, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by master after 143-PR merge marathon 2026-05-31; diff-extract empty.

@lusoris lusoris closed this May 31, 2026
@lusoris
lusoris deleted the docs/per-surface-audit-session-20260529 branch May 31, 2026 13:34
@lusoris
lusoris restored the docs/per-surface-audit-session-20260529 branch May 31, 2026 18:42
@lusoris lusoris reopened this May 31, 2026
@lusoris
lusoris marked this pull request as draft May 31, 2026 18:49
@lusoris

lusoris commented Jun 1, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #527 — bundled per 2026-06-01 triage.

@lusoris lusoris closed this Jun 1, 2026
lusoris added a commit that referenced this pull request Jun 3, 2026
Adds changelog.d/changed/bundle-docs-hygiene.md summarising the
four source PRs: #127 (NOLINT audit), #216 (doc compliance audit),
#291 (state.md drift sweep), #233 (changelog concat fix).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 3, 2026
…291 state.md drift sweep + #233 changelog concat fix) (#527)

* docs(lint): NOLINT cluster audit and refactor plan (ADR-0780)

Swept all 218 NOLINT annotations in core/src/ for clusters of five or more
identical suppressions per file. Identified five clusters (71 annotations):

- 21 bare performance-no-int-to-ptr in GPU slab allocators — ADR-0278
  non-compliant (no citations); scheduled for SLAB_FIELD macro (PR B).
- 12 bugprone-implicit-widening in SYCL stride arithmetic — scheduled for
  explicit (ptrdiff_t) casts that eliminate the suppression entirely (PR A).
- 14 misc-const-correctness in SYCL atomic_ref loops — fold into existing
  NOLINTBEGIN/NOLINTEND block (PR C).
- 13 bare readability-function-size in integer_adm.c — ADR-0278 non-compliant;
  scheduled for NOLINTBEGIN block consolidation (PR C).
- 11 readability-function-size on SYCL kernel entry-points — load-bearing
  per ADR-0141; no change planned.

Deliverables: research digest, ADR-0780 (Proposed), changelog fragment.
Follow-up refactor PRs A–C are independent.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* docs(process): per-surface doc compliance audit — last 30 PRs (ADR-0848)

Audits 30 most recent merged commits (PRs #96–#174) for CLAUDE §12 r10
compliance: user-discoverable surface change must ship human-readable docs
in the same PR.

Score: 22/30 N/A (no surface change), 5/8 with surface changes compliant
(62.5 %). Three confirmed gaps:

- Gap A (HIGH): PR #47 (ADR-0726, Vulkan drop) — docs/backends/vulkan/overview.md,
  docs/metrics/features.md, and docs/development/build-flags.md still describe
  Vulkan as an operative backend. Tracked as T-DOC-VULKAN-STALE-POST-ADR0726.
- Gap B (MEDIUM): PR #87 (ADR-0749, VmafLegacyQualityRunner sunset) — no
  docs/development/deprecations.md entry and no migration note in
  docs/usage/python.md. Tracked as T-DOC-LEGACY-RUNNER-MISSING-DEPRECATION.
- Gap C (LOW): PR #135 (log format standardization) — removes "Error: " prefix
  from CUDA error messages with no doc note.

Three follow-up issues proposed (Issue A, B, C in Research-0848). No code
changes in this PR; audit-only per task brief.

Six deliverables (ADR-0108):
(1) Research-0848: docs/research/research-0848-per-surface-doc-compliance-audit-20260529.md
(2) Decision matrix in ADR-0848 §Alternatives considered
(3) no rebase-sensitive invariants
(4) Reproducer: git log --oneline origin/master | head -30 (auditable from commit list)
(5) changelog.d/changed/per-surface-doc-compliance-audit.md
(6) docs/rebase-notes.md entry added

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* docs(state): close T-LEGACY-RUNNER-ANSNR-BROKEN + T-LEGACY-RUNNER-STUB-MISSING

Both rows referenced classes / imports that no longer exist on master:

1. T-LEGACY-RUNNER-ANSNR-BROKEN — AnsnrFeatureExtractor was deleted
   by PR #283 (merged at faede7a). The class is absent from
   compat/python-vmaf/core/feature_extractor.py on master tip
   d45d503. The Netflix golden assertions still cover the
   integer-path VMAF score (Rule #1 preserved).

2. T-LEGACY-RUNNER-STUB-MISSING-2026-05-29 — VmafLegacyQualityRunner
   import-time failure: the class was removed in ADR-0749 / PR #87
   and python/test/quality_runner_test.py was updated by the
   ADR-0749 sunset PR to drop the import (only a removed-comment
   placeholder at line 49 remains).

Moved both rows from Open to Recently closed with verified-on-master
reproducer commands.

No code changes — documentation cleanup only.

Deliverables (ADR-0108):
- [x] **Research digest**: no digest needed: state.md hygiene
- [x] **Decision matrix**: no alternatives: only-one-way fix
- [x] **AGENTS.md invariant**: no rebase-sensitive invariants
- [x] **Reproducer**: `git show origin/master:compat/python-vmaf/core/feature_extractor.py | grep -c 'class AnsnrFeatureExtractor'` returns 0; `git show origin/master:python/test/quality_runner_test.py | grep -c '^from.*VmafLegacy'` returns 0.
- [x] **Changelog**: changelog.d/changed/state-md-drift-sweep-20260530.md
- [x] **Rebase notes**: no rebase impact: docs only

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* docs(state): migrate 3 Vulkan rows to Recently closed (ADR-0726 supersession)

ADR-0726 (Vulkan backend dropped 2026-05-28, PR #47) structurally closes
three long-standing Vulkan Open rows by removing the affected code path
entirely:

- T-VK-1.4-BUMP — NVIDIA driver 595.71+ FP-contraction regression
- T-VK-CIEDE-F32-F64 — NVIDIA Vulkan f32/f64 ciede precision gap
- T-VK-VIF-1.4-RESIDUAL-ARC — Intel Arc A380 vif residual on Mesa-ANV

The entire `core/src/vulkan/`, `core/src/feature/vulkan/`, and
`core/include/libvmaf/libvmaf_vulkan.h` surface no longer exists on
master, so each row now has a verified empty-path reproducer. Native
CUDA / HIP / SYCL backends cover every vendor formerly served by Vulkan
(see ADR-0726 §Context).

Combined with the legacy-runner closures already in this PR
(T-LEGACY-RUNNER-ANSNR-BROKEN + T-LEGACY-RUNNER-STUB-MISSING-2026-05-29),
this brings the Open section from 14 → 11 rows.

Row counts (verified): Open 11 + Deferred 4 + Recently closed 137 +
Confirmed not-affected 1 = 153 total T- rows in tree.

* chore(changelog): fix concat awk boundary + consolidate perf/ fragments (ADR-0221)

Fix `concat-changelog-fragments.sh` --check/--write awk block-boundary: the
previous `/^## [^[]/` pattern terminated the Unreleased block on any `## Heading`
embedded inside a fragment (e.g. `## Added`, `## [perf] …`). Switch to
`/^## \[(Unreleased|[0-9])/` which matches only versioned-release headers and
the `[Unreleased]` sentinel, making `--check` deterministic. Tightened the
`--write` awk pass with the same fix.

Consolidate 32 fragments from non-standard `changelog.d/perf/` (27) and
`changelog.d/performance/` (5) into the recognised `changed/` section with
`perf-` filename prefix per ADR-0221 KaC convention.

Remove 3 duplicate stubs: `ort-run-stack-arrays-f3b.md`, `adm-pnorm-deferred-comment.md`,
`fixed/vmaf-tune-predictor-directory-corpus.md` (richer versions retained).
Rename `changed/fr-regressor-v3-namespace.md` → `…-adr-appendix.md` to
resolve filename collision with `added/fr-regressor-v3-namespace.md`.

Regenerate CHANGELOG.md Unreleased block via `--write`; `--check` exits 0.

no rebase impact: changelog.d/ + scripts/release/ only, no upstream C touched.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* chore(bundle): add changelog fragment for docs/hygiene bundle PR

Adds changelog.d/changed/bundle-docs-hygiene.md summarising the
four source PRs: #127 (NOLINT audit), #216 (doc compliance audit),
#291 (state.md drift sweep), #233 (changelog concat fix).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Lusoris <lusoris@pm.me>
@lusoris
lusoris deleted the docs/per-surface-audit-session-20260529 branch June 4, 2026 08:10
lusoris added a commit that referenced this pull request Jun 6, 2026
Two Open rows in docs/state.md referred to bugs already in the
Recently Closed section:

- T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 was closed by
  PR #680; the Open row citing "PR #214 (OPEN)" is removed.
- T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 had a stale duplicate
  referencing "PR #215 (OPEN)"; the duplicate is removed. The
  correct owner-driven copy (PR #215 closed without merging,
  fresh PR required) is retained.

T-DOC-LEGACY-RUNNER-MISSING-DEPRECATION-2026-05-29 updated: PR #216
was closed without merging 2026-05-30; the row now reflects that
docs/development/deprecations.md exists (PR #605) but still lacks
the VmafLegacyQualityRunner entry. Owner-driven.

Also fixes a pre-existing data corruption: T-GPU-COVERAGE-STABLE-WEEKS
appeared twice on one line in Recently Closed (no newline separator);
corrected to a single properly-formatted row.

Net Open change: -2 rows.

no digest needed: trivial doc sweep
no alternatives: only-one-way fix
no rebase-sensitive invariants: docs/state.md only

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 6, 2026
…#724)

Two Open rows in docs/state.md referred to bugs already in the
Recently Closed section:

- T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 was closed by
  PR #680; the Open row citing "PR #214 (OPEN)" is removed.
- T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 had a stale duplicate
  referencing "PR #215 (OPEN)"; the duplicate is removed. The
  correct owner-driven copy (PR #215 closed without merging,
  fresh PR required) is retained.

T-DOC-LEGACY-RUNNER-MISSING-DEPRECATION-2026-05-29 updated: PR #216
was closed without merging 2026-05-30; the row now reflects that
docs/development/deprecations.md exists (PR #605) but still lacks
the VmafLegacyQualityRunner entry. Owner-driven.

Also fixes a pre-existing data corruption: T-GPU-COVERAGE-STABLE-WEEKS
appeared twice on one line in Recently Closed (no newline separator);
corrected to a single properly-formatted row.

Net Open change: -2 rows.

no digest needed: trivial doc sweep
no alternatives: only-one-way fix
no rebase-sensitive invariants: docs/state.md only

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 12, 2026
…CI) (#868)

* fix(codeql): resolve HIGH-severity security-cpp-high alerts (23 sites)

- cpp/integer-multiplication-cast-to-long (11): pre-cast one operand to
  size_t / double / ptrdiff_t before int*int multiplications in
  cambi.c, float_vif.c (log message), iqa/convolve.c (img_offset),
  moment.c, psnr.c, and vif_tools.c (four memcpy size expressions).
  Add stddef.h to convolve.c for ptrdiff_t.

- cpp/incomplete-parity-check (3): change `% 2 == 1` to `% 2 != 0`
  in vif_tools.c (assert), svm.cpp (powi loop), pdjson.c (JSON
  object key/value alternation). The == 1 form is wrong for negative
  operands; != 0 is always correct.

- cpp/wrong-type-format-argument (2): fix float_vif.c error log that
  printed size_t fields scaled_w/scaled_h with %d; change to %zu.

- cpp/world-writable-file-creation (1): in vmaf.cpp replace bare
  fopen("wb") with open(O_WRONLY|O_CREAT|O_TRUNC, 0644)+fdopen() on
  POSIX so the created file is never world-writable independent of the
  caller's umask. Add <fcntl.h>.

- cpp/path-injection (4): in test_output.c resolve the mkstemp-created
  path through realpath() immediately after creation, breaking the taint
  chain from getenv("TMPDIR") to the vmaf_write_output call site.

- cpp/toctou-race-condition (2): skipped — both sites are in test
  cleanup (RMDIR after stat assertion). The stat result drives a test
  assertion, not a security-sensitive access decision; no atomic
  replacement of open() is applicable to rmdir. Reported as skipped.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(codeql): resolve security-python-and-ci CodeQL alerts

Fixes 18 open CodeQL alerts across the Python and CI categories:

- yaml.github-actions.security.run-shell-injection (#661): move
  github.event_name, github.base_ref, and github.event.before from
  inline ${{...}} interpolation to env: vars in the SYCL clang-tidy
  detect step of lint-and-format.yml.

- python.lang.security.use-defused-xml-parse (#216, #217): replace
  xml.etree.ElementTree with defusedxml.ElementTree in
  feature_extractor.py and quality_runner.py; add defusedxml>=0.7.1
  to python/pyproject.toml and python/requirements.txt.

- py/undefined-export (#352, #353, #354, #616): restructure
  aiutils/__init__.py to do a conditional eager import of the parquet
  helpers so the names are defined when pyarrow is present, and only
  include them in __all__ when the import succeeded.

- py/stack-trace-exposure (#178, #179, #585): log exception detail
  server-side and return a generic message to the HTTP client in
  http_transport.py _handle_score (invalid JSON, bad params, scorer
  error branches).

- python.lang.security.audit.dangerous-subprocess-use-tainted-env-args
  (#227, #372): add shlex.quote() around user-supplied path arguments
  passed into shell strings in extract_ugc_features.py and
  test_bbb_e2e_v5_bug_cluster.py.

- py/file-not-closed (#677, #678): replace bare open() calls with
  context managers in test_coverage_round3.py.

- py/redundant-comparison (#427, #431): remove redundant
  assert not (x != y) lines that duplicate the preceding assert x == y.

- py/equals-hash-mismatch (#182): convert RdPoint to frozen=True
  dataclass so __eq__ and __hash__ are generated consistently.

- py/inheritance/signature-mismatch (#197): add result_dict=None
  default to EnsembleVmafQualityRunner._populate_result_dict so the
  signature is compatible with the base class.

- py/multiple-definition (#201): drop redundant assignment to
  feature_found in feature_extractor.py wildcard discovery path.

- py/str-format/surplus-named-argument (#204): remove unused
  dataset= kwarg from the format() call in routine.py.

Skipped: python.lang.security.audit.insecure-file-permissions (#373) —
  the Unix socket at 0o660 is intentional (Go sidecar node must write
  to it and runs as the same UNIX group); tightening to 0o644 would
  break the IPC channel.

Skipped: py/path-injection (#180, #181) — _validate_path() already
  resolves the path and checks it against an allowlist before any file
  operation; the data flow is secure and the CodeQL dataflow trace is a
  false positive on this allowlisted pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant